Cisco IOS XR ARP Broadcast Storm Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 7.4 Security Advisory

TL;DR 📌

A denial of service (DoS) vulnerability has been identified in the ARP implementation of Cisco IOS XR Software. An unauthenticated, adjacent attacker can exploit this vulnerability by sending excessive ARP traffic to the management interface, potentially leading to degraded performance or complete unresponsiveness of the device. Cisco has released software updates to address this issue, but no workarounds are available.

What happened 🕵️‍♂️

A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a broadcast storm. This condition can overwhelm the device’s ARP processing capabilities, resulting in a denial of service (DoS). The vulnerability arises when a high volume of ARP traffic is directed at the management interface, leading to degraded performance, loss of management connectivity, and potential system unresponsiveness.

Affected products 🖥️

This vulnerability affects Cisco devices running a vulnerable release of Cisco IOS XR Software with the management interface configured with an IP address in the Up state. Specific vulnerable software releases include:

  • Cisco IOS XR Software Releases 7.11 and earlier
  • 24.1 (Migrate to a fixed release)
  • 24.2 (24.2.21)
  • 24.3 (Migrate to a fixed release)
  • 24.4 (Migrate to a fixed release)
  • 25.1 (25.1.2)
  • 25.2 (25.2.1)

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
7.11 and earlier Migrate to a fixed release.
24.1 Migrate to a fixed release.
24.2 24.2.21
24.3 Migrate to a fixed release.
24.4 Migrate to a fixed release.
25.1 25.1.2
25.2 25.2.1
1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability. Local Packet Transport Services (LPTS) do not provide protection or rate-limiting for traffic received on Management Ethernet (MgmtEth) interfaces.

Risk in context 🎯

The highest CVSS score for this vulnerability is 7.4, which is categorized as High. The risk is primarily driven by the potential for an unauthenticated attacker to exploit the vulnerability through adjacent access, leading to a denial of service. Organizations should prioritize patching affected devices within a week to mitigate this risk.

Fast facts ⚡

  • Vulnerability Type: Denial of Service (DoS)
  • CVSS Score: 7.4 (High)
  • Exploitability: Requires adjacent access, no authentication needed
  • Impact: Degraded performance and potential unresponsiveness
  • Workarounds: None available

For leadership 🧭

Executive summary. Devices running affected Cisco IOS XR releases with an active management interface can be knocked offline by a flood of ARP traffic from anyone on the adjacent network, with no login required and no workaround available. Because there’s no mitigating configuration, patching should be treated as urgent for management-plane availability.

Why it matters:

  • The flaw sits in ARP processing on the Management Ethernet interface itself, so any device on the same broadcast segment can trigger it without credentials.
  • Local Packet Transport Services, which normally rate-limit and protect the control plane, do not cover traffic on MgmtEth interfaces, leaving this path unprotected.
  • Impact ranges from degraded performance to complete unresponsiveness, which for a management interface means losing remote access to the device precisely when you need it.
  • Cisco has confirmed there is no workaround, so exposure persists on unpatched devices until the software is upgraded.

Now / Next / Later:

  • Now: Identify all Cisco IOS XR devices with a management interface configured with an IP address in the Up state and check their software release against the fixed-release table.
  • Next: During the next change window, upgrade each affected device to the first fixed release for its train (e.g. 24.2.21, 25.1.2, or 25.2.1), or migrate off unsupported trains such as 7.11, 24.1, 24.3 and 24.4.
  • Later: Review network segmentation and access controls around management interfaces so that adjacent-segment devices cannot reach MgmtEth directly, reducing exposure to this class of ARP-based issue in future.