• News/
  • https://www.bleepingcomputer.com/news/security/cisco-vulnerability-lets-attackers-crash-bgp-on-ios-xr-routers/

Cisco IOS XR vulnerability lets attackers crash BGP on routers

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 14, 2025
·
Updated

Cisco has patched a denial of service (DoS) vulnerability that lets attackers crash the Border Gateway Protocol (BGP) process on IOS XR routers with a single BGP update message. IOS XR runs on the company's carrier-grade, Network Convergence System (NCS), and Carrier Routing System (CRS) series of routers, such as the ASR 9000, NCS 5500, and 8000 series. This high-severity flaw (tracked as CVE-2025-20115) was found in the confederation implementation for the Border Gateway Protocol (BGP), and it only affects Cisco IOS XR devices if BGP confederation is configured. Successful exploitation allows unauthenticated attackers to take down vulnerable devices remotely in low-complexity attacks by causing memory corruption via buffer overflow, leading to a BGP process restart. "This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers)," the company explains in a security advisory issued this week. "An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more." To exploit the CVE-2025-20115 vulnerability, "the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more," or the attackers must have control of a BGP confederation speaker within the same autonomous system as ...

Read full article

Affected Software

11 affected components
Cisco IOS XR
Cisco NCS 5500
Cisco 8000
Cisco ASR 9000
Cisco CRS
Cisco IOS XR
Cisco NCS
Cisco ASR 9000
Cisco NCS 5500
Cisco 8000 series
Cisco CRS

Frequently Asked Questions

1

What vulnerability is discussed in this article?

The article discusses a denial of service (DoS) vulnerability in Cisco IOS XR that can crash the Border Gateway Protocol (BGP) process.

2

What can attackers do exploiting this vulnerability?

Attackers can crash BGP on IOS XR routers by sending a single malicious BGP update message.

3

Which Cisco products are affected by this vulnerability?

The affected products include Cisco IOS XR, NCS 5500, Cisco 8000 series, ASR 9000, and CRS routers.

4

Has Cisco released a fix for this vulnerability?

Yes, Cisco has released a patch to address the DoS vulnerability in IOS XR.

5

What is the significance of the affected BGP process?

The BGP process is critical for the functioning of the internet as it manages how packets are routed between different networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203