PT-2025-20251 · Cisco · Cisco Ios Xe+2
Published
2025-05-07
·
Updated
2025-05-08
·
CVE-2025-20154
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS Software (affected versions not specified)
Cisco IOS XE Software (affected versions not specified)
Cisco IOS XR Software (affected versions not specified)
Description
A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to out-of-bounds array access when processing specially crafted TWAMP control packets. An attacker could exploit this vulnerability by sending crafted TWAMP control packets to an affected device.
Recommendations
For Cisco IOS Software, update to a version that fixes the vulnerability.
For Cisco IOS XE Software, update to a version that fixes the vulnerability.
For Cisco IOS XR Software, update to a version that fixes the vulnerability, and consider disabling debugs for the ipsla ippm server process as a temporary workaround.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Resource Release
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xe
Cisco Ios Xr