Vulnslist

find the latest Cisco vulnerabilities

Cisco IOS XR ARP Broadcast Storm Denial of Service Vulnerability

cisco-sa-iosxr-arp-storm-EjUU55yM · High · Published · Updated

A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a broadcast storm, leading to a denial of service (DoS) condition on an affected device.  This vulnerability is due to how Cisco IOS XR Software processes a high, sustained rate of ARP traffic hitting the management interface. Under certain conditions, an attacker could exploit this vulnerability by sending an excessive amount of traffic to the management interface of an affected device, overwhelming its ARP processing capabilities. A successful exploit could result in degraded device performance, loss of management connectivity, and complete unresponsiveness of the system, leading to a DoS condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-arp-storm-EjUU55yM This advisory is part of the September 2025 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2025 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication.

Workarounds

There are no workarounds that address this vulnerability.

Note: Local Packet Transport Services (LPTS) do not provide protection or rate-limiting for traffic received on Management Ethernet (MgmtEth) interfaces.

CVEsCVE-2025-20340
Cisco Bug IDsCSCwm86399
CVSS ScoreBase 7.4
Base 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco IOS XR Software, Cisco IOS

Related Products

Product CVE Evidence
Cisco IOS XR Software CVE-2025-20340 Cisco OpenVuln
Cisco IOS CVE-2025-20340 Cisco OpenVuln
Cisco IOS Software CVE-2025-20340 Cisco OpenVuln