EXPOSURES › CVE-2020-3118
CVE-2020-3118
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IOS XR improperly validates CDP input, allowing adjacent attackers to execute admin code or reload devices.
Cisco IOS XR failed to validate string input from Cisco Discovery Protocol messages, enabling unauthenticated adjacent attackers to execute administrative code or reload the device. DIB orgs must care because this is a known, actively exploited vulnerability (KEV) that grants remote code execution and administrative control over network infrastructure, directly impacting compliance with NIST 800-171 controls on system integrity and access control. Organizations should immediately patch affected IOS XR versions and segment adjacent networks to mitigate exposure.
Shame score — A format string vulnerability in widely deployed network infrastructure that was actively exploited in the wild (KEV) allowing unauthenticated adjacent attackers to gain administrative control, representing a severe negligence in patching and input validation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.
"Cisco IOS XR improperly validates string input..."
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |