CVE-2025-20189: High severity cisco ios xe vulnerability
A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper memory management when Cisco IOS XE Software is processing Address Resolution Protocol (ARP) messages. An attacker could exploit this vulnerability by sending crafted ARP messages at a high rate over a period of time to an affected device. A successful exploit could allow the attacker to exhaust system resources, which eventually triggers a reload of the active route switch processor (RSP). If a redundant RSP is not present, the router reloads.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20189?
CVE-2025-20189 has a critical severity rating due to its potential to cause a denial of service condition.
Who is affected by CVE-2025-20189?
CVE-2025-20189 affects Cisco IOS XE Software running on Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C).
How do I fix CVE-2025-20189?
To fix CVE-2025-20189, apply the latest patches and updates provided by Cisco for affected devices.
What type of vulnerability is CVE-2025-20189?
CVE-2025-20189 is a denial of service (DoS) vulnerability that can be triggered by an unauthenticated, adjacent attacker.
Can CVE-2025-20189 be exploited remotely?
No, CVE-2025-20189 requires adjacent access to exploit the vulnerability.