Cyber Resilience

CVE-2025-20145

Cisco Ios Xr 24.1.1 … 7.9.2

Published
12 March 2025
Modified
04 August 2025
Patch / advisory
CVSS Score v3.1 5.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score 0.0039 32th percentile
Risk Priority 46 floored blend · peak EPSS

Summary

CVE-2025-20145 is a medium-severity an unspecified weakness vulnerability in Cisco Ios Xr. Its CVSS base score is 5.8 (Medium).

Operationally, ranked at the 32th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability exists because certain packets are handled incorrectly when they…

more

are received on an ingress interface on one line card and destined out of an egress interface on another line card where the egress ACL is configured. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an egress ACL on the affected device. For more information about this vulnerability, see the section of this advisory. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-20361Same vendor: Cisco
CVE-2023-20190Same product: Cisco Ios Xr
CVE-2019-1620Same vendor: Cisco
CVE-2017-6622Same vendor: Cisco
CVE-2022-20821Same product: Cisco Ios Xr
CVE-2024-20322Same product: Cisco 8608
CVE-2024-20483Same product: Cisco Ios Xr
CVE-2023-20191Same product: Cisco Ios Xr
CVE-2009-2055Same product: Cisco Ios Xr
CVE-2024-20319Same product: Cisco Ios Xr

Affected Assets

cisco
ios xr
24.1.1, 24.1.2, 24.2.1, 24.2.11, 24.2.2

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References