Input validation error in Cisco Systems, Inc products - CVE-2025-20146

 

Input validation error in Cisco Systems, Inc products - CVE-2025-20146

Published: March 13, 2025


Vulnerability identifier: #VU105693
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-20146
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco IOS XR
Cisco ASR 9000 Series Aggregation Services Routers
ASR 9902 Compact High-Performance Routers
ASR 9903 Compact High-Performance Routers

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the incorrect handling of malformed IPv4 multicast packets that are received on line cards where the interface has either an IPv4 access control list (ACL) or a QoS policy applied. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


How to mitigate CVE-2025-20146

Install update from vendor's website.

Sources