Cisco Security Advisory
Follow
Cisco IOS XR Software Image Verification Bypass Vulnerability
A critical vulnerability exists in Cisco IOS XR Software's installation process. This flaw allows an authenticated, local attacker with root privileges to bypass signature verification. By modifying an ISO image and installing it, the attacker can load unsigned software onto the device. This successful exploitation enables the loading of unauthorized files during image activation. Cisco has elevated the Security Impact Rating for this vulnerability to High due to the bypassed image verification. Software updates are available to address this issue. Unfortunately, there are no workarounds to mitigate this specific vulnerability. This advisory, identified as CVE-2025-20248, is part of a larger security publication. Cisco advises users to apply the provided software updates promptly. The advisory can be found at the provided Cisco security center link.