EXPOSURES › CVE-2020-3566
CVE-2020-3566
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IOS XR DVMRP mishandles IGMP packets, allowing remote attackers to crash the IGMP process or exhaust memory.
This memory exhaustion vulnerability in Cisco IOS XR's DVMRP protocol lets unauthenticated remote attackers crash the IGMP process or deplete system memory. For DIB organizations, this means network infrastructure could be destabilized by remote actors, potentially disrupting critical communications and violating availability requirements under NIST 800-171. Organizations must ensure all Cisco IOS XR devices are patched to the latest versions and restrict unnecessary IGMP traffic.
Shame score — A known, actively exploited vulnerability in critical network infrastructure that could be leveraged for denial-of-service or as a foothold for further attacks, reflecting systemic patching and input validation issues.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |