PT-2025-11103 · Cisco · Cisco Ios Xr
Published
2025-03-12
·
Updated
2025-08-06
·
CVE-2025-20177
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XR Software (affected versions not specified)
Description:
A vulnerability in the boot process could allow an authenticated, local attacker to bypass image signature verification and load unverified software on an affected device. The attacker must have root-system privileges on the affected device. This issue is due to incomplete validation of files in the boot verification process, allowing an attacker to manipulate system configuration options and bypass integrity checks during the boot process. A successful exploit could enable the attacker to control the boot configuration, bypass the requirement to run Cisco-signed images, or alter the security properties of the running system.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xr