SB2025031278 - Secure boot bypass in Cisco IOS XR



SB2025031278 - Secure boot bypass in Cisco IOS XR

Published: March 12, 2025

Security Bulletin ID SB2025031278
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2025-20143)

The vulnerability allows a local user to bypass security boot protections.

The vulnerability exists due to improper cryptographic signature verification of modules in the software load process. A local user can bypass some of the integrity checks that are performed during the booting process and compromise the affected system.

This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco IOS XR Software, regardless of device configuration:

  • ASR 9000 Series Aggregation Services Routers (64-bit)
  • IOS XRv 9000 Routers
  • Network Convergence System (NCS) 540 Series Routers that are running an NCS540-iosxr base image
  • NCS 560 Series Routers
  • NCS 1000 Series
  • NCS 5000 Series Routers
  • NCS 5500 Series Routers


Remediation

Install update from vendor's website.