Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2025-20177

 

Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2025-20177

Published: March 13, 2025


Vulnerability identifier: #VU105699
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20177
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to incomplete validation of files in the boot verification process. A local administrator can control the boot configuration, which could enable them to bypass the requirement to run Cisco-signed images or alter the security properties of the running system.


Affected software

Cisco IOS XR
Cisco 8000 Series Routers
NCS 5700 Series Routers
NCS540
NCS 1010
NCS 1014

How to mitigate CVE-2025-20177

Install updates from vendor's website.

Cisco IOS XR - addressed in versions 7.11.21, 24.2.2, 24.2.20, 24.3.2, 24.3.20, 24.4.1, 24.4.10

External References

Related Security Bulletins