PT-2025-11101 · Cisco · Cisco Ios Xr

Published

2024-09-02

·

Updated

2025-08-04

·

CVE-2025-20145

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Cisco IOS XR Software (affected versions not specified)
Description: A vulnerability in the access control list (ACL) processing in the egress direction could allow an unauthenticated, remote attacker to bypass a configured ACL. This issue arises from incorrect handling of certain packets received on an ingress interface on one line card and destined out of an egress interface on another line card where the egress ACL is configured. An attacker could exploit this by sending traffic through an affected device, potentially bypassing an egress ACL.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-02698
CVE-2025-20145

Affected Products

Cisco Ios Xr