Skip to content
COOEY

EXPOSURES › CVE-2020-3118

CVE-2020-3118

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-3118 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrce

Cisco IOS XR improperly validates CDP input, allowing adjacent attackers to execute admin code or reload devices.

Cisco IOS XR failed to validate string input from Cisco Discovery Protocol messages, enabling unauthenticated adjacent attackers to execute administrative code or reload the device. DIB orgs must care because this is a known, actively exploited vulnerability (KEV) that grants remote code execution and administrative control over network infrastructure, directly impacting compliance with NIST 800-171 controls on system integrity and access control. Organizations should immediately patch affected IOS XR versions and segment adjacent networks to mitigate exposure.

Shame score — A format string vulnerability in widely deployed network infrastructure that was actively exploited in the wild (KEV) allowing unauthenticated adjacent attackers to gain administrative control, representing a severe negligence in patching and input validation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Criticized for validation failure
cooey ↗ severe-fallout -0.70
Highlights validation failure
"Cisco IOS XR improperly validates string input..."
AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized