← All CVEs

CVE-2020-3566

high · 8.6Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.

8.6
CVSS
3.7%
EPSS (exploit prob.)
89th
EPSS percentile
2020-08-29
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses

CWE-400CWE-770

Affected products

VendorProductAffected versions
ciscoios_xr6.4.2
ciscoasr_9001all versions
ciscoasr_9006all versions
ciscoasr_9010all versions
ciscoasr_9901all versions
ciscoasr_9904all versions
ciscoasr_9906all versions
ciscoasr_9910all versions
ciscoasr_9912all versions
ciscoasr_9922all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-3566