Junglewise Threat Intelligence

CVE-2020-3569: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

CVE-2020-3569 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2021-11-03

Technologies: Cisco IOS XR Software, Cisco IOS XR. Vendors: Cisco.

Executive brief

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software allows unauthenticated remote attackers to cause a denial of service. By sending crafted IGMP packets, an attacker can crash the IGMP process or exhaust system memory, potentially destabilizing other routing protocols.

Affected products

  • Cisco IOS XR Software 6.1.4, 6.2.3, 6.3.3, 6.4.2, 6.5.3, 6.6.2, 6.6.3, 7.0.2, 7.1.2, 7.1.15

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats