CVE-2025-20115
Description
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to restart, resulting in a DoS condition. To exploit this vulnerability, an attacker must control a BGP confederation speaker within the same autonomous system as the victim, or the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more.
CVSS Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Threat Intelligence
Weaknesses 1
Affected Products 93
| Vendor | Product | Version | Range |
|---|---|---|---|
| cisco | ios_xr | 6.5.1 | any |
| cisco | ios_xr | 6.5.2 | any |
| cisco | ios_xr | 6.5.3 | any |
| cisco | ios_xr | 6.5.15 | any |
| cisco | ios_xr | 6.5.25 | any |
| cisco | ios_xr | 6.5.26 | any |
| cisco | ios_xr | 6.5.28 | any |
| cisco | ios_xr | 6.5.29 | any |
| cisco | ios_xr | 6.5.31 | any |
| cisco | ios_xr | 6.5.32 | any |
| cisco | ios_xr | 6.5.33 | any |
| cisco | ios_xr | 6.5.35 | any |
| cisco | ios_xr | 6.5.90 | any |
| cisco | ios_xr | 6.5.92 | any |
| cisco | ios_xr | 6.5.93 | any |
| cisco | ios_xr | 6.6.1 | any |
| cisco | ios_xr | 6.6.2 | any |
| cisco | ios_xr | 6.6.3 | any |
| cisco | ios_xr | 6.6.4 | any |
| cisco | ios_xr | 6.6.11 | any |
| cisco | ios_xr | 6.6.12 | any |
| cisco | ios_xr | 6.6.25 | any |
| cisco | ios_xr | 6.7.1 | any |
| cisco | ios_xr | 6.7.2 | any |
| cisco | ios_xr | 6.7.3 | any |
| cisco | ios_xr | 6.7.4 | any |
| cisco | ios_xr | 6.7.35 | any |
| cisco | ios_xr | 6.8.1 | any |
| cisco | ios_xr | 6.8.2 | any |
| cisco | ios_xr | 6.9.1 | any |
| cisco | ios_xr | 6.9.2 | any |
| cisco | ios_xr | 7.0.0 | any |
| cisco | ios_xr | 7.0.1 | any |
| cisco | ios_xr | 7.0.2 | any |
| cisco | ios_xr | 7.0.11 | any |
| cisco | ios_xr | 7.0.12 | any |
| cisco | ios_xr | 7.0.14 | any |
| cisco | ios_xr | 7.0.90 | any |
| cisco | ios_xr | 7.1.1 | any |
| cisco | ios_xr | 7.1.2 | any |
| cisco | ios_xr | 7.1.3 | any |
| cisco | ios_xr | 7.1.15 | any |
| cisco | ios_xr | 7.1.25 | any |
| cisco | ios_xr | 7.2.0 | any |
| cisco | ios_xr | 7.2.1 | any |
| cisco | ios_xr | 7.2.2 | any |
| cisco | ios_xr | 7.2.12 | any |
| cisco | ios_xr | 7.3.1 | any |
| cisco | ios_xr | 7.3.2 | any |
| cisco | ios_xr | 7.3.3 | any |
| cisco | ios_xr | 7.3.4 | any |
| cisco | ios_xr | 7.3.5 | any |
| cisco | ios_xr | 7.3.6 | any |
| cisco | ios_xr | 7.3.15 | any |
| cisco | ios_xr | 7.3.16 | any |
| cisco | ios_xr | 7.3.27 | any |
| cisco | ios_xr | 7.4.1 | any |
| cisco | ios_xr | 7.4.2 | any |
| cisco | ios_xr | 7.4.15 | any |
| cisco | ios_xr | 7.4.16 | any |
| cisco | ios_xr | 7.5.1 | any |
| cisco | ios_xr | 7.5.2 | any |
| cisco | ios_xr | 7.5.3 | any |
| cisco | ios_xr | 7.5.4 | any |
| cisco | ios_xr | 7.5.5 | any |
| cisco | ios_xr | 7.5.12 | any |
| cisco | ios_xr | 7.5.52 | any |
| cisco | ios_xr | 7.6.1 | any |
| cisco | ios_xr | 7.6.2 | any |
| cisco | ios_xr | 7.6.3 | any |
| cisco | ios_xr | 7.6.15 | any |
| cisco | ios_xr | 7.7.1 | any |
| cisco | ios_xr | 7.7.2 | any |
| cisco | ios_xr | 7.7.21 | any |
| cisco | ios_xr | 7.8.1 | any |
| cisco | ios_xr | 7.8.2 | any |
| cisco | ios_xr | 7.8.12 | any |
| cisco | ios_xr | 7.8.22 | any |
| cisco | ios_xr | 7.8.23 | any |
| cisco | ios_xr | 7.9.1 | any |
| cisco | ios_xr | 7.9.2 | any |
| cisco | ios_xr | 7.9.21 | any |
| cisco | ios_xr | 7.10.1 | any |
| cisco | ios_xr | 7.10.2 | any |
| cisco | ios_xr | 7.11.1 | any |
| cisco | ios_xr | 7.11.2 | any |
| cisco | ios_xr | 7.11.21 | any |
| cisco | ios_xr | 24.1.1 | any |
| cisco | ios_xr | 24.1.2 | any |
| cisco | ios_xr | 24.2.1 | any |
| cisco | ios_xr | 24.2.2 | any |
| cisco | ios_xr | 24.2.11 | any |
| cisco | ios_xr | 24.2.20 | any |
References 2
- blog.apnic.net https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp/
- sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-bgp-dos-O7stePhX
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.