THREAT OPS › Threat News › [NVD] CVE-2025-20248 (MEDIUM 6.0) — A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have r
[NVD] CVE-2025-20248 (MEDIUM 6.0) — A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have r
CVE-2025-20248 CVSS: 6.0 MEDIUM Published: 2025-09-10T16:15:36.117
A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device.
Thi
Indicators of compromise
- CVE-2025-20248cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-20248