Language:
http://www.nessus.org/u?f091a92e
http://www.nessus.org/u?402ef3d6
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj33398
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwm56977
Severity: High
ID: 274616
File Name: cisco-sa-iosxr-priv-esc-GFQjxvOF-iosxr.nasl
Version: 1.2
Type: combined
Family: CISCO
Published: 11/10/2025
Updated: 11/18/2025
Supported Sensors: Nessus
Risk Factor: High
Score: 7.3
Risk Factor: Medium
Base Score: 6.8
Temporal Score: 5
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
CVSS Score Source: CVE-2025-20138
Risk Factor: High
Base Score: 8.8
Temporal Score: 7.7
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
CPE: cpe:/o:cisco:ios_xr
Required KB Items: Host/Cisco/IOS-XR/Version
Exploit Ease: No known exploits are available
Patch Publication Date: 3/12/2025
Vulnerability Publication Date: 3/12/2025
CVE: CVE-2025-20138
CWE: 78
CISCO-SA: cisco-sa-iosxr-priv-esc-GFQjxvOF
IAVA: 2025-A-0159-S
CISCO-BUG-ID: CSCwj33398, CSCwm56977, CSCwm85670, CSCwm85686