Cisco fixes high-severity IOS XR flaws enabling image bypass and DoS
ID: 86f6ad16-4f65-5b2e-a23e-a04e007388b3
STIX ID: report--86f6ad16-4f65-5b2e-a23e-a04e007388b3
Feed Name: Security Affairs
Cisco released patches for multiple IOS XR vulnerabilities: CVE-2025-20340 (high) in ARP processing that can allow an unauthenticated adjacent attacker to cause broadcast storms and denial-of-service, CVE-2025-20248 (high) in the ISO installation process that can bypass image signature checks and permit unsigned files to be installed (requires root-system privileges), and CVE-2025-20159 (medium) enabling ACL bypass on the management interface; Cisco reports no known in-the-wild exploitation and urges operators to apply the fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
