Cisco IOS, IOS XE, and IOS XR Software TWAMP Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS and IOS XE Software. This vulnerability allows an unauthenticated, remote attacker to cause the affected device to reload, leading to a DoS condition. In Cisco IOS XR Software, the vulnerability can cause the ipsla_ippm_server process to reload unexpectedly, but only if debugs are enabled. The issue arises from out-of-bounds array access when processing specially crafted TWAMP control packets. An attacker could exploit this vulnerability by sending these crafted packets to an affected device.

Impact

Exploitation of this vulnerability causes the affected device to reload, resulting in a denial-of-service condition. In Cisco IOS XR Software, only the ipsla_ippm_server process reloads unexpectedly and only when debugs are enabled.

Remediation

Cisco has released free software updates that address this vulnerability. Customers with service contracts should obtain these security fixes through their usual update channels. For information on which Cisco software releases are vulnerable, consult the 'Fixed Software' section of the advisory.

Added: Jun 5, 2025, 11:38 PM
Updated: Jun 6, 2025, 12:13 AM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
7.8
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.