CVE-2025-20115 | Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability

A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to restart, resulting in a DoS condition. To exploit this vulnerability, an attacker must control a BGP confederation speaker within the same autonomous system as the victim, or the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more.

Published: 2025-03-12 Last update: 2025-08-01 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-20115 is rated Moderate Risk (62.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.37%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2025-20115

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-15 1.72% 1.37% -0.35%
2 2026-05-07 1.77% 1.72% -0.05%
3 2026-04-24 1.77%

Full EPSS history (22 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-20115

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.6 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 4.0 [email protected]

Weakness enumeration for CVE-2025-20115

Affected software / configurations for CVE-2025-20115

Vendor Product Version Raw CPE
cisco ios_xr 6.5.1 cpe:2.3:o:cisco:ios_xr:6.5.1:*:*:*:*:*:*:*
cisco ios_xr 6.5.2 cpe:2.3:o:cisco:ios_xr:6.5.2:*:*:*:*:*:*:*
cisco ios_xr 6.5.3 cpe:2.3:o:cisco:ios_xr:6.5.3:*:*:*:*:*:*:*
cisco ios_xr 6.5.15 cpe:2.3:o:cisco:ios_xr:6.5.15:*:*:*:*:*:*:*
cisco ios_xr 6.5.25 cpe:2.3:o:cisco:ios_xr:6.5.25:*:*:*:*:*:*:*
cisco ios_xr 6.5.26 cpe:2.3:o:cisco:ios_xr:6.5.26:*:*:*:*:*:*:*
cisco ios_xr 6.5.28 cpe:2.3:o:cisco:ios_xr:6.5.28:*:*:*:*:*:*:*
cisco ios_xr 6.5.29 cpe:2.3:o:cisco:ios_xr:6.5.29:*:*:*:*:*:*:*
cisco ios_xr 6.5.31 cpe:2.3:o:cisco:ios_xr:6.5.31:*:*:*:*:*:*:*
cisco ios_xr 6.5.32 cpe:2.3:o:cisco:ios_xr:6.5.32:*:*:*:*:*:*:*
cisco ios_xr 6.5.33 cpe:2.3:o:cisco:ios_xr:6.5.33:*:*:*:*:*:*:*
cisco ios_xr 6.5.35 cpe:2.3:o:cisco:ios_xr:6.5.35:*:*:*:*:*:*:*
cisco ios_xr 6.5.90 cpe:2.3:o:cisco:ios_xr:6.5.90:*:*:*:*:*:*:*
cisco ios_xr 6.5.92 cpe:2.3:o:cisco:ios_xr:6.5.92:*:*:*:*:*:*:*
cisco ios_xr 6.5.93 cpe:2.3:o:cisco:ios_xr:6.5.93:*:*:*:*:*:*:*
cisco ios_xr 6.6.1 cpe:2.3:o:cisco:ios_xr:6.6.1:*:*:*:*:*:*:*
cisco ios_xr 6.6.2 cpe:2.3:o:cisco:ios_xr:6.6.2:*:*:*:*:*:*:*
cisco ios_xr 6.6.3 cpe:2.3:o:cisco:ios_xr:6.6.3:*:*:*:*:*:*:*
cisco ios_xr 6.6.4 cpe:2.3:o:cisco:ios_xr:6.6.4:*:*:*:*:*:*:*
cisco ios_xr 6.6.11 cpe:2.3:o:cisco:ios_xr:6.6.11:*:*:*:*:*:*:*
cisco ios_xr 6.6.12 cpe:2.3:o:cisco:ios_xr:6.6.12:*:*:*:*:*:*:*
cisco ios_xr 6.6.25 cpe:2.3:o:cisco:ios_xr:6.6.25:*:*:*:*:*:*:*
cisco ios_xr 6.7.1 cpe:2.3:o:cisco:ios_xr:6.7.1:*:*:*:*:*:*:*
cisco ios_xr 6.7.2 cpe:2.3:o:cisco:ios_xr:6.7.2:*:*:*:*:*:*:*
cisco ios_xr 6.7.3 cpe:2.3:o:cisco:ios_xr:6.7.3:*:*:*:*:*:*:*
cisco ios_xr 6.7.4 cpe:2.3:o:cisco:ios_xr:6.7.4:*:*:*:*:*:*:*
cisco ios_xr 6.7.35 cpe:2.3:o:cisco:ios_xr:6.7.35:*:*:*:*:*:*:*
cisco ios_xr 6.8.1 cpe:2.3:o:cisco:ios_xr:6.8.1:*:*:*:*:*:*:*
cisco ios_xr 6.8.2 cpe:2.3:o:cisco:ios_xr:6.8.2:*:*:*:*:*:*:*
cisco ios_xr 6.9.1 cpe:2.3:o:cisco:ios_xr:6.9.1:*:*:*:*:*:*:*
cisco ios_xr 6.9.2 cpe:2.3:o:cisco:ios_xr:6.9.2:*:*:*:*:*:*:*
cisco ios_xr 7.0.0 cpe:2.3:o:cisco:ios_xr:7.0.0:*:*:*:*:*:*:*
cisco ios_xr 7.0.1 cpe:2.3:o:cisco:ios_xr:7.0.1:*:*:*:*:*:*:*
cisco ios_xr 7.0.2 cpe:2.3:o:cisco:ios_xr:7.0.2:*:*:*:*:*:*:*
cisco ios_xr 7.0.11 cpe:2.3:o:cisco:ios_xr:7.0.11:*:*:*:*:*:*:*
cisco ios_xr 7.0.12 cpe:2.3:o:cisco:ios_xr:7.0.12:*:*:*:*:*:*:*
cisco ios_xr 7.0.14 cpe:2.3:o:cisco:ios_xr:7.0.14:*:*:*:*:*:*:*
cisco ios_xr 7.0.90 cpe:2.3:o:cisco:ios_xr:7.0.90:*:*:*:*:*:*:*
cisco ios_xr 7.1.1 cpe:2.3:o:cisco:ios_xr:7.1.1:*:*:*:*:*:*:*
cisco ios_xr 7.1.2 cpe:2.3:o:cisco:ios_xr:7.1.2:*:*:*:*:*:*:*
cisco ios_xr 7.1.3 cpe:2.3:o:cisco:ios_xr:7.1.3:*:*:*:*:*:*:*
cisco ios_xr 7.1.15 cpe:2.3:o:cisco:ios_xr:7.1.15:*:*:*:*:*:*:*
cisco ios_xr 7.1.25 cpe:2.3:o:cisco:ios_xr:7.1.25:*:*:*:*:*:*:*
cisco ios_xr 7.2.0 cpe:2.3:o:cisco:ios_xr:7.2.0:*:*:*:*:*:*:*
cisco ios_xr 7.2.1 cpe:2.3:o:cisco:ios_xr:7.2.1:*:*:*:*:*:*:*
cisco ios_xr 7.2.2 cpe:2.3:o:cisco:ios_xr:7.2.2:*:*:*:*:*:*:*
cisco ios_xr 7.2.12 cpe:2.3:o:cisco:ios_xr:7.2.12:*:*:*:*:*:*:*
cisco ios_xr 7.3.1 cpe:2.3:o:cisco:ios_xr:7.3.1:*:*:*:*:*:*:*
cisco ios_xr 7.3.2 cpe:2.3:o:cisco:ios_xr:7.3.2:*:*:*:*:*:*:*
cisco ios_xr 7.3.3 cpe:2.3:o:cisco:ios_xr:7.3.3:*:*:*:*:*:*:*
cisco ios_xr 7.3.4 cpe:2.3:o:cisco:ios_xr:7.3.4:*:*:*:*:*:*:*
cisco ios_xr 7.3.5 cpe:2.3:o:cisco:ios_xr:7.3.5:*:*:*:*:*:*:*
cisco ios_xr 7.3.6 cpe:2.3:o:cisco:ios_xr:7.3.6:*:*:*:*:*:*:*
cisco ios_xr 7.3.15 cpe:2.3:o:cisco:ios_xr:7.3.15:*:*:*:*:*:*:*
cisco ios_xr 7.3.16 cpe:2.3:o:cisco:ios_xr:7.3.16:*:*:*:*:*:*:*
cisco ios_xr 7.3.27 cpe:2.3:o:cisco:ios_xr:7.3.27:*:*:*:*:*:*:*
cisco ios_xr 7.4.1 cpe:2.3:o:cisco:ios_xr:7.4.1:*:*:*:*:*:*:*
cisco ios_xr 7.4.2 cpe:2.3:o:cisco:ios_xr:7.4.2:*:*:*:*:*:*:*
cisco ios_xr 7.4.15 cpe:2.3:o:cisco:ios_xr:7.4.15:*:*:*:*:*:*:*
cisco ios_xr 7.4.16 cpe:2.3:o:cisco:ios_xr:7.4.16:*:*:*:*:*:*:*
cisco ios_xr 7.5.1 cpe:2.3:o:cisco:ios_xr:7.5.1:*:*:*:*:*:*:*
cisco ios_xr 7.5.2 cpe:2.3:o:cisco:ios_xr:7.5.2:*:*:*:*:*:*:*
cisco ios_xr 7.5.3 cpe:2.3:o:cisco:ios_xr:7.5.3:*:*:*:*:*:*:*
cisco ios_xr 7.5.4 cpe:2.3:o:cisco:ios_xr:7.5.4:*:*:*:*:*:*:*
cisco ios_xr 7.5.5 cpe:2.3:o:cisco:ios_xr:7.5.5:*:*:*:*:*:*:*
cisco ios_xr 7.5.12 cpe:2.3:o:cisco:ios_xr:7.5.12:*:*:*:*:*:*:*
cisco ios_xr 7.5.52 cpe:2.3:o:cisco:ios_xr:7.5.52:*:*:*:*:*:*:*
cisco ios_xr 7.6.1 cpe:2.3:o:cisco:ios_xr:7.6.1:*:*:*:*:*:*:*
cisco ios_xr 7.6.2 cpe:2.3:o:cisco:ios_xr:7.6.2:*:*:*:*:*:*:*
cisco ios_xr 7.6.3 cpe:2.3:o:cisco:ios_xr:7.6.3:*:*:*:*:*:*:*
cisco ios_xr 7.6.15 cpe:2.3:o:cisco:ios_xr:7.6.15:*:*:*:*:*:*:*
cisco ios_xr 7.7.1 cpe:2.3:o:cisco:ios_xr:7.7.1:*:*:*:*:*:*:*
cisco ios_xr 7.7.2 cpe:2.3:o:cisco:ios_xr:7.7.2:*:*:*:*:*:*:*
cisco ios_xr 7.7.21 cpe:2.3:o:cisco:ios_xr:7.7.21:*:*:*:*:*:*:*
cisco ios_xr 7.8.1 cpe:2.3:o:cisco:ios_xr:7.8.1:*:*:*:*:*:*:*
cisco ios_xr 7.8.2 cpe:2.3:o:cisco:ios_xr:7.8.2:*:*:*:*:*:*:*
cisco ios_xr 7.8.12 cpe:2.3:o:cisco:ios_xr:7.8.12:*:*:*:*:*:*:*
cisco ios_xr 7.8.22 cpe:2.3:o:cisco:ios_xr:7.8.22:*:*:*:*:*:*:*
cisco ios_xr 7.8.23 cpe:2.3:o:cisco:ios_xr:7.8.23:*:*:*:*:*:*:*
cisco ios_xr 7.9.1 cpe:2.3:o:cisco:ios_xr:7.9.1:*:*:*:*:*:*:*

References for CVE-2025-20115

cvelogic Threat Intelligence