Skip to content
COOEY

FAIL › dossier

IOS XR

PRODUCT

· dossier confidence 40%

Cisco IOS XR is a critical networking operating system with a documented history of high-severity vulnerabilities in core routing protocols and system components. The security track record shows repeated issues with remote code execution, denial-of-service, and improper input validation that allow adjacent attackers to execute admin code or reload devices.

PROFILE
CategorynetworkingWhat they doCisco IOS XR is an operating system for Cisco routers and switches, providing advanced routing and network management capabilities.Founded1984 Websitehttps://www.cisco.com ↗
SECURITY POSTURE

The security posture is characterized by a history of high-severity vulnerabilities in core routing protocols and system components, including remote code execution, denial-of-service, and improper input validation that allow adjacent attackers to execute admin code or reload devices.

Notable failures
  • CVE-2020-3118: CDP input validation RCE allowing admin code execution
  • CVE-2022-20821: Redis port 6379 exposed by default enabling container access
  • CVE-2020-3566: DVMRP IGMP mishandling causing process crashes and memory exhaustion
Patterns: repeated unpatched edge-device RCEs; improper input validation in routing protocols; default-exposed container ports
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2020-3118 high Cisco IOS XR improperly validates CDP input, allowing adjacent attackers to execute admin code or reload devices.
2022-05-23 CVE-2022-20821 high Cisco IOS XR software health check opens TCP port 6379 by default, allowing attackers to access the Redis instance running within the NOSi container.
2022-03-25 CVE-2010-3035 high Cisco IOS XR BGP allows remote attackers to cause a denial-of-service attack.
2022-03-25 CVE-2009-2055 high Cisco IOS XR BGP allows remote attackers to cause a denial-of-service attack.
2021-11-03 CVE-2020-3566 high Cisco IOS XR DVMRP mishandles IGMP packets, allowing remote attackers to crash the IGMP process or exhaust memory.
2021-11-03 CVE-2020-3569 high Cisco IOS XR DVMRP mishandles IGMP packets, allowing remote attackers to crash the IGMP process or exhaust memory.
Open questions: Current patch status for CVE-2020-3118 and CVE-2022-20821 · Specific remediation steps taken for NOSi container exposure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:51:18.148067+00:00