CVE-2025-20154

HIGH

Cisco IOS XR - Unauthenticated Denial of Service via TWAMP Control Packet Processing

Title source: llm
STIX 2.1

Description

A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this vulnerability could cause the ipsla_ippm_server process to reload unexpectedly if debugs are enabled. This vulnerability is due to out-of-bounds array access when processing specially crafted TWAMP control packets. An attacker could exploit this vulnerability by sending crafted TWAMP control packets to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: For Cisco IOS XR Software, only the ipsla_ippm_server process reloads unexpectedly and only when debugs are enabled. The vulnerability details for Cisco IOS XR Software are as follows:    Security Impact Rating (SIR): Low    CVSS Base Score: 3.7    CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Scores

CVSS v3 8.6
EPSS 0.0045
EPSS Percentile 63.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Products (50)
cisco/ios < 15.9\(3\)m11
cisco/ios_xe 16.6.1 - 17.2.3
cisco/ios_xr 6.5.1
cisco/ios_xr 6.5.2
cisco/ios_xr 6.5.3
cisco/ios_xr 6.5.15
cisco/ios_xr 6.5.25
cisco/ios_xr 6.5.26
cisco/ios_xr 6.5.28
cisco/ios_xr 6.5.29
... and 40 more
Published May 07, 2025
Tracked Since Feb 18, 2026