CVE-2020-3118 KEV
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 11.69% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | none known |
| Published | 2020-02-05 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco IOS XR Software Discovery Protocol Format String Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Cisco / IOS XR |
| Ransomware use | none reported |
Affected (37)
| Vendor | Product |
|---|---|
| cisco | asr 9000 |
| cisco | asr 9000v |
| cisco | asr 9001 |
| cisco | asr 9006 |
| cisco | asr 9010 |
| cisco | asr 9901 |
| cisco | asr 9903 |
| cisco | asr 9904 |
| cisco | asr 9906 |
| cisco | asr 9910 |
| cisco | asr 9912 |
| cisco | asr 9920 |
| cisco | asr 9922 |
| cisco | crs-x |
| cisco | ios xr |
| cisco | ncs 540-12z20g-sys-a |
| cisco | ncs 540-12z20g-sys-d |
| cisco | ncs 540-24z8q2c-sys |
| cisco | ncs 540-28z4c-sys-a |
| cisco | ncs 540-28z4c-sys-d |
| cisco | ncs 540-acc-sys |
| cisco | ncs 540l |
| cisco | ncs 540x-12z16g-sys-a |
| cisco | ncs 540x-12z16g-sys-d |
| cisco | ncs 540x-16z4g8q2c-a |
| cisco | ncs 540x-16z4g8q2c-d |
| cisco | ncs 540x-acc-sys |
| cisco | ncs 5501 |
| cisco | ncs 5501-se |
| cisco | ncs 5502 |
| cisco | ncs 5502-se |
| cisco | ncs 5508 |
| cisco | ncs 5516 |
| cisco | ncs 560 |
| cisco | ncs 6000 |
| cisco | ncs 6008 |
| cisco | xrv 9000 |
References
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200205-iosxr-cdp-rce
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200205-iosxr-cdp-rce
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3118
→ the Explorer · watch your stack · NVD