CVE-2025-20115

A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to restart, resulting in a DoS condition. To exploit this vulnerability, an attacker must control a BGP confederation speaker within the same autonomous system as the victim, or the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
ciscoCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
ciscoios_xr
6.5.1
ciscoios_xr
6.5.2
ciscoios_xr
6.5.3
ciscoios_xr
6.5.15
ciscoios_xr
6.5.25
ciscoios_xr
6.5.26
ciscoios_xr
6.5.28
ciscoios_xr
6.5.29
ciscoios_xr
6.5.31
ciscoios_xr
6.5.32
ciscoios_xr
6.5.33
ciscoios_xr
6.5.35
ciscoios_xr
6.5.90
ciscoios_xr
6.5.92
ciscoios_xr
6.5.93
ciscoios_xr
6.6.1
ciscoios_xr
6.6.2
ciscoios_xr
6.6.3
ciscoios_xr
6.6.4
ciscoios_xr
6.6.11
ciscoios_xr
6.6.12
ciscoios_xr
6.6.25
ciscoios_xr
6.7.1
ciscoios_xr
6.7.2
ciscoios_xr
6.7.3
ciscoios_xr
6.7.4
ciscoios_xr
6.7.35
ciscoios_xr
6.8.1
ciscoios_xr
6.8.2
ciscoios_xr
6.9.1
ciscoios_xr
6.9.2
ciscoios_xr
7.0.0
ciscoios_xr
7.0.1
ciscoios_xr
7.0.2
ciscoios_xr
7.0.11
ciscoios_xr
7.0.12
ciscoios_xr
7.0.14
ciscoios_xr
7.0.90
ciscoios_xr
7.1.1
ciscoios_xr
7.1.2
ciscoios_xr
7.1.3
ciscoios_xr
7.1.15
ciscoios_xr
7.1.25
ciscoios_xr
7.2.0
ciscoios_xr
7.2.1
ciscoios_xr
7.2.2
ciscoios_xr
7.2.12
ciscoios_xr
7.3.1
ciscoios_xr
7.3.2
ciscoios_xr
7.3.3
ciscoios_xr
7.3.4
ciscoios_xr
7.3.5
ciscoios_xr
7.3.6
ciscoios_xr
7.3.15
ciscoios_xr
7.3.16
ciscoios_xr
7.3.27
ciscoios_xr
7.4.1
ciscoios_xr
7.4.2
ciscoios_xr
7.4.15
ciscoios_xr
7.4.16
ciscoios_xr
7.5.1
ciscoios_xr
7.5.2
ciscoios_xr
7.5.3
ciscoios_xr
7.5.4
ciscoios_xr
7.5.5
ciscoios_xr
7.5.12
ciscoios_xr
7.5.52
ciscoios_xr
7.6.1
ciscoios_xr
7.6.2
ciscoios_xr
7.6.3
ciscoios_xr
7.6.15
ciscoios_xr
7.7.1
ciscoios_xr
7.7.2
ciscoios_xr
7.7.21
ciscoios_xr
7.8.1
ciscoios_xr
7.8.2
ciscoios_xr
7.8.12
ciscoios_xr
7.8.22
ciscoios_xr
7.8.23
ciscoios_xr
7.9.1
ciscoios_xr
7.9.2
ciscoios_xr
7.9.21
ciscoios_xr
7.10.1
ciscoios_xr
7.10.2
ciscoios_xr
7.11.1
ciscoios_xr
7.11.2
ciscoios_xr
7.11.21
ciscoios_xr
24.1.1
ciscoios_xr
24.1.2
ciscoios_xr
24.2.1
ciscoios_xr
24.2.2
ciscoios_xr
24.2.11
ciscoios_xr
24.2.20
𝑥
= Vulnerable software versions