Junglewise Threat Intelligence

CVE-2020-3566: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

CVE-2020-3566 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2021-11-03

Technologies: Cisco IOS XR, Cisco IOS XR Software. Vendors: Cisco.

Executive brief

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software allows an unauthenticated, remote attacker to exhaust process memory. The issue stems from insufficient queue management for IGMP packets, which can lead to process instability or crashes in routing protocols.

Affected products

  • Cisco IOS XR Software 6.4.2 and others

Timeline

  • 2020-08-29: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Advisory published/updated date provided in text
  • 2021-11-03: exploited: Reported as exploited in the wild in the advisory summary and CISA KEV catalog.

Related threats