THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-20248 (MEDIUM 6.0) — A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have r

[NVD] CVE-2025-20248 (MEDIUM 6.0) — A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have r

lownvdPublished 2025-09-10

CVE-2025-20248 CVSS: 6.0 MEDIUM Published: 2025-09-10T16:15:36.117

A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device.

Thi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-20248