Input validation error in Cisco Systems, Inc products - CVE-2025-20154

 

Input validation error in Cisco Systems, Inc products - CVE-2025-20154

Published: May 9, 2025


Vulnerability identifier: #VU108835
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20154
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the Two-Way Active Measurement Protocol (TWAMP) server feature. A remote attacker can send specially crafted TWAMP control packets and perform a denial of service (DoS) attack.


Affected software

Cisco IOS XR
Cisco IOS XE
Cisco IOS Software

How to mitigate CVE-2025-20154

Install updates from vendor's website.

Cisco IOS XR - addressed in versions 24.3.2, 24.3.20, 24.4.1, 24.4.2, 24.4.10, 25.1.1
Cisco IOS XE - addressed in versions 16.6.1, 16.6.1a, 16.6.2, 16.6.2s, 16.6.3, 16.6.4, 16.6.4s, 16.6.4a, 16.6.5, 16.6.5a, 16.6.5b, 16.6.6, 16.6.7, 16.6.7a, 16.6.8, 16.6.9, 16.6.10, 16.7.1, 16.7.1a, 16.7.1b, 16.7.2, 16.7.3, 16.7.4, 16.8.1, 16.8.1c, 16.8.1d, 16.8.1e, 16.8.1s, 16.8.1a, 16.8.1b, 16.8.2, 16.8.3, 16.9.1, 16.9.1c, 16.9.1d, 16.9.1s, 16.9.1a, 16.9.1b, 16.9.2, 16.9.2s, 16.9.2a, 16.9.3, 16.9.3h, 16.9.3s, 16.9.3a, 16.9.4, 16.9.4c, 16.9.5, 16.9.5f, 16.9.6, 16.9.7, 16.9.8, 16.9.8a, 16.9.8b, 16.10.1, 16.10.1c, 16.10.1d, 16.10.1e, 16.10.1f, 16.10.1g, 16.10.1i, 16.10.1s, 16.10.1a, 16.10.1b, 16.10.2, 16.10.3, 16.11.1, 16.11.1c, 16.11.1s, 16.11.1a, 16.11.1b, 16.11.2, 16.12.1, 16.12.1c, 16.12.1s, 16.12.1t, 16.12.1v, 16.12.1w, 16.12.1x, 16.12.1y, 16.12.1z, 16.12.1z1, 16.12.1z2, 16.12.1a, 16.12.2, 16.12.2s, 16.12.2t, 16.12.2a, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 16.12.5 b, 16.12.6, 16.12.6a, 16.12.7, 16.12.8, 16.12.9, 16.12.10, 16.12.10a, 16.12.11, 16.12.12, 17.1.1, 17.1.1s, 17.1.1t, 17.1.1a, 17.1.2, 17.1.3, 17.2.1, 17.2.1v, 17.2.1LA, 17.2.1a, 17.2.1r, 17.2.2, 17.2.3, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1z, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.3.3a, 17.3.4, 17.3.4c, 17.3.4a, 17.3.4 b, 17.3.5, 17.3.5a, 17.3.5b, 17.3.6, 17.3.7, 17.3.8, 17.3.8a, 17.4.1, 17.4.1c, 17.4.1a, 17.4.1b, 17.4.2, 17.4.2a, 17.5.1, 17.5.1c, 17.05.01c, 17.5.1a, 17.5.1b, 17.6.1, 17.6.1w, 17.6.1x, 17.6.1y, 17.6.1z, 17.6.1z1, 17.6.1a, 17.6.2, 17.6.3, 17.6.3a, 17.6.4, 17.6.5, 17.6.5a, 17.6.6, 17.6.6a, 17.6.7, 17.6.8, 17.6.8a, 17.7.1, 17.7.1a, 17.7.1b, 17.7.2, 17.8.1, 17.8.1a, 17.9.1, 17.9.1w, 17.9.1x, 17.9.1x1, 17.9.1y, 17.9.1y1, 17.9.1a, 17.9.2, 17.9.2a, 17.9.3, 17.9.3a, 17.9.4, 17.9.4a, 17.9.5, 17.9.5c, 17.9.5d, 17.9.5a, 17.9.5b, 17.9.6, 17.9.6a, 17.10.1, 17.10.1a, 17.10.1b, 17.11.1, 17.11.1a, 17.12.1, 17.12.1w, 17.12.1x, 17.12.1y, 17.12.1z, 17.12.1z1, 17.12.2, 17.12.2a, 17.12.02a, 17.12.3, 17.12.3a, 17.12.4, 17.13.1, 17.13.1a, 17.14.1, 17.14.1a, 17.15.1, 17.15.1w, 17.15.1a, 17.15.1b
Cisco IOS Software - addressed in versions Dublin-17.12.5, Cupertino-17.9.6, 16.12.13, 17.9.6, 17.9.6a, 17.9.6b, 17.9.7, 17.9.7a, 17.12.1z2, 17.12.1z3, 17.12.5, 17.12.5a, 17.15.1x, 17.15.1y, 17.15.2, 17.15.2c, 17.15.2a, 17.15.2b, 17.15.3, 17.16.1, 17.16.1a, 17.17.1

External References

Related Security Bulletins