Cisco has patched a denial of service (DoS) vulnerability that lets attackers crash the Border Gateway Protocol (BGP) process on IOS XR routers with a single BGP update message. IOS XR runs on the company's carrier-grade, Network Convergence System (NCS), and Carrier Routing System (CRS) series of routers, such as the ASR 9000, NCS 5500, and 8000 series. This high-severity flaw (tracked as CVE-2025-20115) was found in the confederation implementation for the Border Gateway Protocol (BGP), and it only affects Cisco IOS XR devices if BGP confederation is configured. Successful exploitation allows unauthenticated attackers to take down vulnerable devices remotely in low-complexity attacks by causing memory corruption via buffer overflow, leading to a BGP process restart. "This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers)," the company explains in a security advisory issued this week. "An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more." To exploit the CVE-2025-20115 vulnerability, "the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more," or the attackers must have control of a BGP confederation speaker within the same autonomous system as ...
Cisco IOS XR vulnerability lets attackers crash BGP on routers
BleepingComputer
·Sergiu Gatlan
·Published Mar 14, 2025
·Updated
Affected Software
11 affected components
Cisco IOS XR
Cisco NCS 5500
Cisco 8000
Cisco ASR 9000
Cisco CRS
Cisco IOS XR
Cisco NCS
Cisco ASR 9000
Cisco NCS 5500
Cisco 8000 series
Cisco CRS
Frequently Asked Questions
1
What vulnerability is discussed in this article?
The article discusses a denial of service (DoS) vulnerability in Cisco IOS XR that can crash the Border Gateway Protocol (BGP) process.
2
What can attackers do exploiting this vulnerability?
Attackers can crash BGP on IOS XR routers by sending a single malicious BGP update message.
3
Which Cisco products are affected by this vulnerability?
The affected products include Cisco IOS XR, NCS 5500, Cisco 8000 series, ASR 9000, and CRS routers.
4
Has Cisco released a fix for this vulnerability?
Yes, Cisco has released a patch to address the DoS vulnerability in IOS XR.
5
What is the significance of the affected BGP process?
The BGP process is critical for the functioning of the internet as it manages how packets are routed between different networks.