PT-2025-11101 · Cisco · Cisco Ios Xr
Published
2024-09-02
·
Updated
2025-08-04
·
CVE-2025-20145
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XR Software (affected versions not specified)
Description:
A vulnerability in the access control list (ACL) processing in the egress direction could allow an unauthenticated, remote attacker to bypass a configured ACL. This issue arises from incorrect handling of certain packets received on an ingress interface on one line card and destined out of an egress interface on another line card where the egress ACL is configured. An attacker could exploit this by sending traffic through an affected device, potentially bypassing an egress ACL.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xr