Skip to content
COOEY

EXPOSURES › CVE-2020-3569

CVE-2020-3569

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-3569 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Cisco IOS XR DVMRP mishandles IGMP packets, allowing remote attackers to crash the IGMP process or exhaust memory.

This memory exhaustion vulnerability in Cisco IOS XR's DVMRP protocol lets unauthenticated remote attackers crash the IGMP process or deplete system memory. For DIB organizations, this means network infrastructure could be destabilized by remote actors, potentially disrupting critical communications and violating availability requirements under NIST 800-171. Organizations must ensure all Cisco IOS XR devices are patched to the latest versions and restrict unnecessary IGMP traffic.

Shame score — A known, actively exploited vulnerability in critical network infrastructure that could be leveraged for denial-of-service or as a foothold for further attacks, reflecting systemic patching and input validation failures.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -1.00
negative
"…"
AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized