CVE-2025-20248Medium· 6.0▾ SunlitA vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device.
This vulnerability is due to incomplete validation of files during the installation of an .iso file. An attacker could exploit this vulnerability by modifying contents of the .iso image and then installing and activating it on the device. A successful exploit could allow the attacker to load an unsigned file as part of the image activation process.
ios_xr = 6.5.1ios_xr = 6.5.2ios_xr = 6.5.3ios_xr = 6.5.15ios_xr = 6.5.25ios_xr = 6.5.26ios_xr = 6.5.28ios_xr = 6.5.29ios_xr = 6.5.31ios_xr = 6.5.32ios_xr = 6.5.33ios_xr = 6.5.35ios_xr = 6.5.90ios_xr = 6.5.92ios_xr = 6.5.93ios_xr = 6.5.351ios_xr = 6.5.352ios_xr = 6.6.1ios_xr = 6.6.2ios_xr = 6.6.3ios_xr = 6.6.4ios_xr = 6.6.11ios_xr = 6.6.12ios_xr = 6.6.25ios_xr = 6.7.1ios_xr = 6.7.2ios_xr = 6.7.3ios_xr = 6.7.35ios_xr = 6.8.1ios_xr = 6.8.2ios_xr = 6.9.1ios_xr = 6.9.2ios_xr = 7.0.0ios_xr = 7.0.1ios_xr = 7.0.2ios_xr = 7.0.90ios_xr = 7.1.1ios_xr = 7.1.2ios_xr = 7.1.3ios_xr = 7.1.15ios_xr = 7.1.25ios_xr = 7.2.0ios_xr = 7.2.1ios_xr = 7.2.2ios_xr = 7.3.1ios_xr = 7.3.2ios_xr = 7.3.3ios_xr = 7.3.4ios_xr = 7.3.5ios_xr = 7.3.6ios_xr = 7.3.27ios_xr = 7.4.1ios_xr = 7.4.2ios_xr = 7.4.15ios_xr = 7.4.16ios_xr = 7.5.1ios_xr = 7.5.2ios_xr = 7.5.3ios_xr = 7.5.4ios_xr = 7.5.5ios_xr = 7.6.1ios_xr = 7.6.2ios_xr = 7.6.3ios_xr = 7.6.15ios_xr = 7.7.1ios_xr = 7.7.2ios_xr = 7.7.21ios_xr = 7.8.1ios_xr = 7.8.2ios_xr = 7.8.22ios_xr = 7.8.23ios_xr = 7.9.1ios_xr = 7.9.2ios_xr = 7.9.21ios_xr = 7.10.1ios_xr = 7.10.2ios_xr = 7.11.1ios_xr = 7.11.2ios_xr = 7.11.21ios_xr = 24.1.1ios_xr = 24.1.2ios_xr = 24.2.1ios_xr = 24.2.2ios_xr = 24.2.11ios_xr = 24.2.20ios_xr = 24.3.1ios_xr = 24.3.2ios_xr = 24.4.1ios_xr = 24.4.10ios_xr = 24.4.15Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3138Medium· 6.7A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading
CVE-2020-3308Medium· 4.9A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an a…
CVE-2026-20276High· 8.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review
CVE-2026-20280High· 8.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review
CVE-2026-20274Critical· 9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review
CVE-2026-20074High· 7.4A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. Th…