CVE-2025-20189

HIGH

Cisco IOS XE for ASR 903 with RSP3C - Unauthenticated Denial of Service via ARP Message Processing

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper memory management when Cisco IOS XE Software is processing Address Resolution Protocol (ARP) messages. An attacker could exploit this vulnerability by sending crafted ARP messages at a high rate over a period of time to an affected device. A successful exploit could allow the attacker to exhaust system resources, which eventually triggers a reload of the active route switch processor (RSP). If a redundant RSP is not present, the router reloads.

Scores

CVSS v3 7.4
EPSS 0.0010
EPSS Percentile 27.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-762
Status published
Products (50)
cisco/ios_xe 3.16.0cs
cisco/ios_xe 3.16.0s
cisco/ios_xe 3.16.1as
cisco/ios_xe 3.16.1s
cisco/ios_xe 3.16.2as
cisco/ios_xe 3.16.2bs
cisco/ios_xe 3.16.2s
cisco/ios_xe 3.16.3as
cisco/ios_xe 3.16.3s
cisco/ios_xe 3.16.4as
... and 40 more
Published May 07, 2025
Tracked Since Feb 18, 2026