Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-20145

CVE-2025-20145: Cisco IOS XR Auth Bypass Vulnerability

CVE-2025-20145 is an authentication bypass flaw in Cisco IOS XR Software that allows attackers to circumvent egress ACL controls. This article covers the technical details, affected versions, and mitigation steps.

Published:

CVE-2025-20145 Overview

CVE-2025-20145 is an access control list (ACL) bypass vulnerability in Cisco IOS XR Software. The flaw exists in the egress-direction ACL processing on multi-line-card platforms. An unauthenticated, remote attacker can send traffic through an affected device and bypass a configured egress ACL. The issue occurs when packets ingress on one line card and are destined out an egress interface on a different line card that has the ACL configured. Cisco has published software updates to address the vulnerability, and no workarounds are available.

Critical Impact

Attackers can reach network segments or services that operators believed were filtered, undermining perimeter and segmentation controls enforced through egress ACLs on affected Cisco IOS XR routers.

Affected Products

  • Cisco IOS XR Software (multiple releases from 6.5.1 through 24.4.1)
  • Cisco 8000 Series Routers (8608, 8804, 8808, 8812, 8818)
  • Cisco Network Convergence System 5500 Series (NCS 5504, NCS 5508, NCS 5516)

Discovery Timeline

  • 2025-03-12 - CVE-2025-20145 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-20145

Vulnerability Analysis

The vulnerability affects how Cisco IOS XR Software handles packets that traverse two different line cards within the same chassis. When a packet enters an ingress interface on one line card and is forwarded out an egress interface on a separate line card, the egress ACL configured on that outbound interface is not applied correctly. Traffic that should be dropped by the egress filter is instead forwarded. The weakness is classified as CWE-264 (Permissions, Privileges, and Access Controls). It affects broadly deployed service provider platforms, including the Cisco 8000 Series and NCS 5500 Series, across dozens of IOS XR release trains. Because the flaw is a data-plane forwarding defect, exploitation requires no authentication and no user interaction — only the ability to send packets through the router.

Root Cause

The root cause is incorrect packet handling in the modular, distributed forwarding path. Egress ACL enforcement logic is not consistently applied to packets that cross the internal fabric between line cards. On single-line-card paths the ACL is enforced correctly, which is why the issue is limited to inter-line-card flows.

Attack Vector

An attacker sends crafted traffic through an affected device toward a destination protected by an egress ACL configured on a different line card than the ingress interface. The traffic transits the router as if the ACL entry did not exist. Refer to the Cisco Security Advisory for technical details on affected configurations.

No public proof-of-concept code is available, and there are no verified code samples to reproduce here.

Detection Methods for CVE-2025-20145

Indicators of Compromise

  • Traffic observed at internal or downstream monitoring points that should have been blocked by an egress ACL on an affected Cisco IOS XR device.
  • Unexpected flows appearing in NetFlow, IPFIX, or sFlow telemetry between source and destination pairs that violate documented ACL policy.
  • Hit counters on egress ACL entries that do not increment despite policy-violating traffic being observed elsewhere.

Detection Strategies

  • Compare intended ACL policy against actual forwarded traffic using flow telemetry exported from the router and correlated in a SIEM or data lake.
  • Run periodic reachability tests from external test sources through the router to targets that should be blocked by egress ACLs on cross-line-card paths.
  • Inventory IOS XR versions with show version and match against the fixed releases listed in the Cisco advisory to identify exposed devices.

Monitoring Recommendations

  • Enable and forward NetFlow or IPFIX from all affected routers to a centralized analytics platform for continuous policy validation.
  • Alert on any traffic matching deny rules that reaches destinations beyond the router, indicating filter bypass.
  • Monitor Cisco PSIRT advisories and syslog output for configuration changes to ACLs on affected chassis.

How to Mitigate CVE-2025-20145

Immediate Actions Required

  • Identify Cisco 8000 Series and NCS 5500 Series routers running affected IOS XR versions and prioritize them for patching.
  • Upgrade to a fixed Cisco IOS XR release as identified in the Cisco Security Advisory.
  • Where feasible, apply equivalent filtering at ingress interfaces on the same line card as a compensating control until patching is complete.

Patch Information

Cisco has released software updates that resolve CVE-2025-20145. Fixed release information is documented in the Cisco Security Advisory cisco-sa-modular-ACL-u5MEPXMm. Administrators should download the appropriate fixed image for their platform and IOS XR train and schedule an upgrade window.

Workarounds

  • No workarounds address this vulnerability, per Cisco's advisory.
  • As a partial risk-reduction step, configure ingress ACLs on the same line card as the source interface to enforce policy before the packet traverses the fabric.
  • Restrict physical and logical access to interfaces that can inject traffic into affected devices while patches are being deployed.

Refer to Cisco documentation for platform-specific upgrade procedures. No configuration example is provided because no configuration change mitigates this vulnerability.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.