Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2025-20248

 

Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2025-20248

Published: September 11, 2025


Vulnerability identifier: #VU115156
CSH Severity:
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20248
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to incomplete validation of files during the installation of an .iso file. A local administrator can load an unsigned file as part of the image activation process.


Affected software

IOS XR White box
NCS 1000 Series
NCS 6000 Series Routers
NCS 5700 Series Routers
NCS 5000
Cisco Network Convergence System 540 Series Routers
Cisco IOS XRv 9000 Router
Cisco ASR 9000 Series Aggregation Services Routers
NCS5500
NCS560
Cisco IOS XR

How to mitigate CVE-2025-20248

Install updates from vendor's website.

Cisco IOS XR - addressed in versions 24.2.21, 24.3.20, 24.3.30, 24.4.2, 24.4.30, 25.1.1, 25.1.2, 25.2.1

External References

Related Security Bulletins