Executive brief
A format string vulnerability in the Cisco Discovery Protocol (CDP) implementation of Cisco IOS XR Software allows an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a device reload. The flaw exists due to improper validation of string input in certain CDP message fields, which can lead to a stack overflow.
Affected products
- Cisco IOS XR Software 5.2.5, 6.4.2, 6.5.2, 6.5.3
Timeline
- 2020-02-05: advisory: Initial vendor advisory published by Cisco
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed