CVE-2020-3566 KEV
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.
Scoring
| CVSS | 8.6 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| EPSS | 3.7% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-400 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | none known |
| Published | 2020-08-29 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Cisco / IOS XR |
| Ransomware use | none reported |
Affected (10)
| Vendor | Product |
|---|---|
| cisco | asr 9001 |
| cisco | asr 9006 |
| cisco | asr 9010 |
| cisco | asr 9901 |
| cisco | asr 9904 |
| cisco | asr 9906 |
| cisco | asr 9910 |
| cisco | asr 9912 |
| cisco | asr 9922 |
| cisco | ios xr |
References
→ the Explorer · watch your stack · NVD