PT-2025-20251 · Cisco · Cisco Ios Xe+2

Published

2025-05-07

·

Updated

2025-05-08

·

CVE-2025-20154

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS Software (affected versions not specified) Cisco IOS XE Software (affected versions not specified) Cisco IOS XR Software (affected versions not specified)
Description A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to out-of-bounds array access when processing specially crafted TWAMP control packets. An attacker could exploit this vulnerability by sending crafted TWAMP control packets to an affected device.
Recommendations For Cisco IOS Software, update to a version that fixes the vulnerability. For Cisco IOS XE Software, update to a version that fixes the vulnerability. For Cisco IOS XR Software, update to a version that fixes the vulnerability, and consider disabling debugs for the ipsla ippm server process as a temporary workaround. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Resource Release

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-10320
CVE-2025-20154

Affected Products

Cisco Ios
Cisco Ios Xe
Cisco Ios Xr