logo

Cisco fixes high-severity IOS XR flaws enabling image bypass and DoS

ID: 86f6ad16-4f65-5b2e-a23e-a04e007388b3

STIX ID: report--86f6ad16-4f65-5b2e-a23e-a04e007388b3

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2025-09-12

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco released patches for multiple IOS XR vulnerabilities: CVE-2025-20340 (high) in ARP processing that can allow an unauthenticated adjacent attacker to cause broadcast storms and denial-of-service, CVE-2025-20248 (high) in the ISO installation process that can bypass image signature checks and permit unsigned files to be installed (requires root-system privileges), and CVE-2025-20159 (medium) enabling ACL bypass on the management interface; Cisco reports no known in-the-wild exploitation and urges operators to apply the fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.