Cisco IOS XR Software Management Interface ACL Bypass Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 5.3 Security Advisory

TL;DR 📌

A medium-severity vulnerability in Cisco IOS XR Software allows unauthenticated remote attackers to bypass access control lists (ACLs) on the management interface for SSH, NetConf, and gRPC features. Users are advised to upgrade to fixed software releases or implement workarounds.

What happened 🕵️‍♂️

A vulnerability was identified in the management interface ACL processing feature of Cisco IOS XR Software. This flaw allows unauthenticated remote attackers to bypass configured ACLs, potentially leading to unauthorized access to management features like SSH, NetConf, and gRPC. The issue arises because management interface ACLs are not enforced on certain Linux-handled features within the Packet I/O infrastructure.

Affected products 🖥️

The vulnerability affects the following Cisco platforms and IOS XR Software releases with an IPv4 or IPv6 ACL attached to the management interface:

  • 8000 Series Routers (Software image earlier than the first fixed release)
  • ASR 9000 Series Routers (Releases 24.1.1 and later but earlier than the first fixed release)
  • IOS XR White box (Releases 7.9.1 and later but earlier than the first fixed release)
  • IOS XRd vRouters (Software image earlier than the first fixed release)
  • IOS XRv 9000 Routers (Releases 24.1.1 and later but earlier than the first fixed release)
  • NCS 540 Series Routers (NCS540-iosxr base image) (Releases 7.9.1 and later but earlier than the first fixed release)
  • NCS 540 Series Routers (NCS540L-iosxr base image) (All releases earlier than the first fixed release)
  • NCS 560 Series Routers (Releases 24.2.1 and later but earlier than the first fixed release)
  • NCS 1010 Platforms (Software image earlier than the first fixed release)
  • NCS 1014 Platforms (Software image earlier than the first fixed release)
  • NCS 5500 Series Routers (Releases 7.9.1 and later but earlier than the first fixed release)
  • NCS 5700 Series Routers (NCS5700 base image earlier than the first fixed release)

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
Cisco IOS XR Software Management Interface ACL Bypass Vulnerability 25.2.1 25.1.1
Cisco IOS XR Software Management Interface ACL Bypass Vulnerability 25.2.1 Not affected

Workarounds 🧯

There are no workarounds for attaching the IPv4 or IPv6 ACL to the management interface to block gRPC, SSH, or NETCONF over SSH. Customers must migrate to a fixed release that introduces support for this feature. However, a workaround is available for customers unable to upgrade; they should contact the Cisco Technical Assistance Center (TAC) for coordination.

Risk in context 🎯

The vulnerability has a CVSS score of 5.3, indicating a medium risk. It allows unauthenticated access and could lead to unauthorized control over management features, impacting network security. The exposure is primarily driven by the management interfaces being accessible over the network. Immediate remediation is recommended through software upgrades or contacting TAC for workarounds.

Fast facts ⚡

  • Vulnerability: ACL Bypass in Cisco IOS XR Software
  • CVSS Score: 5.3 (Medium)
  • Exploitation: Unauthenticated remote access possible
  • Affected Features: SSH, NetConf, gRPC
  • Remediation: Upgrade to fixed releases or contact TAC for workarounds

For leadership 🧭

Executive summary. Routers across the Cisco IOS XR range that rely on management-interface ACLs to restrict SSH, NetConf and gRPC access are not actually protected, letting unauthenticated network reachability substitute for the intended access control. There is no interim workaround for this specific gap, so the fix requires either an upgrade or a coordinated TAC engagement, and it should be scheduled promptly rather than treated as background patching.

Why it matters:

  • The ACL bypass affects the management interface specifically, meaning the controls operators put in place to limit who can reach SSH, NetConf and gRPC administrative access are silently ineffective.
  • No authentication is required to exploit the gap, so anyone with network reachability to the management interface can attempt access that the ACL was meant to block.
  • The affected list spans most current IOS XR platforms, including 8000, ASR 9000, NCS 540/560/1010/1014/5500/5700 series and IOS XRv 9000/XRd/White box images, so a large installed base is in scope.
  • There is no configuration workaround for blocking gRPC, SSH or NetConf over SSH via ACL; remediation depends on upgrading to a fixed release or arranging a TAC-provided interim mitigation.

Now / Next / Later:

  • Now: placeholder
  • Next: placeholder
  • Later: placeholder