Vulnerability Description
A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms. This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | 7.9.2 |
| Cisco | Ncs 540-12Z20G-Sys-A | - |
| Cisco | Ncs 540-12Z20G-Sys-D | - |
| Cisco | Ncs 540-24Q2C2Dd-Sys | - |
| Cisco | Ncs 540-24Q8L2Dd-Sys | - |
| Cisco | Ncs 540-24Z8Q2C-Sys | - |
| Cisco | Ncs 540-28Z4C-Sys-A | - |
| Cisco | Ncs 540-28Z4C-Sys-D | - |
| Cisco | Ncs 540-6Z14S-Sys-D | - |
| Cisco | Ncs 540-6Z18G-Sys-A | - |
| Cisco | Ncs 540-6Z18G-Sys-D | - |
| Cisco | Ncs 540-Acc-Sys | - |
| Cisco | Ncs 540-Fh-Agg | - |
| Cisco | Ncs 540-Fh-Csr-Sys | - |
| Cisco | Ncs 540X-12Z16G-Sys-A | - |
| Cisco | Ncs 540X-12Z16G-Sys-D | - |
| Cisco | Ncs 540X-16Z4G8Q2C-A | - |
| Cisco | Ncs 540X-16Z4G8Q2C-D | - |
| Cisco | Ncs 540X-16Z8Q2C-D | - |
| Cisco | Ncs 540X-4Z14G2Q-A | - |
Related Weaknesses (CWE)
References
- https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp/Product
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
FAQ
What is CVE-2025-20141?
CVE-2025-20141 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to ca...
How severe is CVE-2025-20141?
CVE-2025-20141 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-20141?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xr, Cisco Ncs 540-12Z20G-Sys-A, Cisco Ncs 540-12Z20G-Sys-D, Cisco Ncs 540-24Q2C2Dd-Sys, Cisco Ncs 540-24Q8L2Dd-Sys.