CVE-2025-20159
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-10

Last updated on: 2025-09-11

Assigner: Cisco Systems, Inc.

Description
A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass configured ACLs for the SSH, NetConf, and gRPC features. This vulnerability exists because management interface ACLs have not been supported on Cisco IOS XR Software Packet I/O infrastructure platforms for Linux-handled features such as SSH, NetConf, or gRPC. An attacker could exploit this vulnerability by attempting to send traffic to an affected device. A successful exploit could allow the attacker to bypass an ingress ACL that is applied on the management interface of the affected device.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-10
Last Modified
2025-09-11
Generated
2026-05-27
AI Q&A
2025-09-10
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
cisco ios_xr 25.2.2
cisco ios_xr 25.1.1
cisco ios_xr 25.1.2
cisco ios_xr 24.2.21
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-20159 is a medium-severity vulnerability in Cisco IOS XR Software where the management interface access control lists (ACLs) do not properly enforce restrictions on Linux-handled features such as SSH, NetConf, and gRPC. This means an unauthenticated remote attacker can bypass these ACLs on the management interface and potentially send unauthorized traffic to the device. The root cause is that ACLs applied to the management interface are not supported or enforced for these protocols within the Packet I/O infrastructure, allowing attackers to circumvent intended access controls. [1]


How can this vulnerability impact me? :

This vulnerability can allow an unauthenticated remote attacker to bypass ingress ACLs on the management interface for SSH, NetConf, and gRPC services. As a result, the attacker could potentially gain unauthorized access or control over the affected Cisco IOS XR device by sending traffic that should have been blocked by the ACLs. This could lead to unauthorized configuration changes, data exposure, or disruption of network management functions. [1]


How can this vulnerability be detected on my network or system? Can you suggest some commands?

To detect this vulnerability, check if IP ACLs are applied to the management interface blocking gRPC, SSH, or NetConf ports. Use the following commands to verify configurations: - `show running-config interface mgmtEth <value>` to check ACLs on the management interface. - `show running-config grpc` and `show running-config linux networking` to verify gRPC and Traffic Protection configurations. - `show running-config ssh` to verify SSH configuration and confirm IP ACLs applied to SSH service. - `show running-config ssh server netconf` to verify NetConf over SSH configuration and confirm IP ACLs applied. These commands help determine if the device is vulnerable due to missing ACL enforcement on Linux-handled features. [1]


What immediate steps should I take to mitigate this vulnerability?

Immediate mitigation steps include: - Upgrade affected Cisco IOS XR Software to fixed releases that support management interface ACL enforcement for SSH, NetConf, and gRPC. The fixed releases vary by platform but generally start from releases 25.1.1 or 25.1.2 and later. - For SSH and NetConf, configure ingress ACLs under SSH server configuration mode using commands such as `ssh server vrf <vrf-name> ipv4 access-list <acl-name>` and/or `ipv6 access-list <acl-name>`, and enable filtering with `ssh server packet-flow-netio ingress` on supported releases. - For gRPC, filtering is supported only from certain releases and requires Traffic Protection for Linux Networking. - If upgrading is not immediately possible, contact Cisco TAC for coordinated workaround implementation, understanding that workarounds may impact network functionality or performance. - Verify device compatibility and memory before upgrading and consult Cisco TAC for assistance. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart