CVE-2025-20115High· 8.6▾ MidnightPoC availableA vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to a …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.3 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.9%
1 GitHub repo (last check)
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to restart, resulting in a DoS condition. To exploit this vulnerability, an attacker must control a BGP confederation speaker within the same autonomous system as the victim, or the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more.
Cisco has released software updates that address this vulnerability. There is a workaround that addresses this vulnerability.
This advisory is part of the March 2025 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: March 2025 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication ["https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75548"].
Cisco IOS XR Software Border Gateway Protocol Confederation Denial of Service Vulnerability. Released 2025-03-12.
Affected:
Cisco has released software updates that address this vulnerability. https://software.cisco.com
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-20142High· 8.6Cisco IOS XR Software for ASR 9000 Series Routers L2VPN Denial of Service Vulnerability
CVE-2025-20143Medium· 6.7Cisco IOS XR Software Secure Boot Bypass Vulnerability (CVE-2025-20143)
CVE-2025-20146High· 8.6Cisco IOS XR Software for ASR 9000 Series Routers Layer 3 Multicast Routing Denial of Service Vulnerability
CVE-2024-20304High· 8.6Cisco IOS XR Software Packet Memory Exhaustion Vulnerability
CVE-2024-20398High· 8.8Cisco IOS XR Software Local Privilege Escalation Vulnerability
CVE-2024-20390Medium· 5.3Cisco IOS XR Software Dedicated XML Agent TCP Denial of Service Vulnerability (CVE-2024-20390)