Input validation error in Cisco Systems, Inc products - CVE-2025-20154
Published: May 9, 2025
Cisco IOS XE
Cisco IOS XR
Cisco IOS Software
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the Two-Way Active Measurement Protocol (TWAMP) server feature. A remote attacker can send specially crafted TWAMP control packets and perform a denial of service (DoS) attack.