peter bassill · operator
$ cve CVE-2020-3566 JSON

CVE-2020-3566 KEV

8.6
HIGH · CVSS 3.1 · EPSS 3.7% (pctl 89)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.

Scoring

CVSS8.6 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS3.7% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-400
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2020-08-29
Last modified2026-06-17

CISA KEV

NameCisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productCisco / IOS XR
Ransomware usenone reported

Affected (10)

VendorProduct
ciscoasr 9001
ciscoasr 9006
ciscoasr 9010
ciscoasr 9901
ciscoasr 9904
ciscoasr 9906
ciscoasr 9910
ciscoasr 9912
ciscoasr 9922
ciscoios xr

References

→ the Explorer  ·  watch your stack  ·  NVD