FAIL › dossier
IOS XR
PRODUCT· dossier confidence 40%
Cisco IOS XR is a critical networking operating system with a documented history of high-severity vulnerabilities in core routing protocols and system components. The security track record shows repeated issues with remote code execution, denial-of-service, and improper input validation that allow adjacent attackers to execute admin code or reload devices.
PROFILE
CategorynetworkingWhat they doCisco IOS XR is an operating system for Cisco routers and switches, providing advanced routing and network management capabilities.Founded1984
Websitehttps://www.cisco.com ↗
SECURITY POSTURE
The security posture is characterized by a history of high-severity vulnerabilities in core routing protocols and system components, including remote code execution, denial-of-service, and improper input validation that allow adjacent attackers to execute admin code or reload devices.
Notable failures
- CVE-2020-3118: CDP input validation RCE allowing admin code execution
- CVE-2022-20821: Redis port 6379 exposed by default enabling container access
- CVE-2020-3566: DVMRP IGMP mishandling causing process crashes and memory exhaustion
Patterns: repeated unpatched edge-device RCEs; improper input validation in routing protocols; default-exposed container ports
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2020-3118 | high | Cisco IOS XR improperly validates CDP input, allowing adjacent attackers to execute admin code or reload devices. |
| 2022-05-23 | CVE-2022-20821 | high | Cisco IOS XR software health check opens TCP port 6379 by default, allowing attackers to access the Redis instance running within the NOSi container. |
| 2022-03-25 | CVE-2010-3035 | high | Cisco IOS XR BGP allows remote attackers to cause a denial-of-service attack. |
| 2022-03-25 | CVE-2009-2055 | high | Cisco IOS XR BGP allows remote attackers to cause a denial-of-service attack. |
| 2021-11-03 | CVE-2020-3566 | high | Cisco IOS XR DVMRP mishandles IGMP packets, allowing remote attackers to crash the IGMP process or exhaust memory. |
| 2021-11-03 | CVE-2020-3569 | high | Cisco IOS XR DVMRP mishandles IGMP packets, allowing remote attackers to crash the IGMP process or exhaust memory. |
DOSSIER SOURCES
- Cisco - Wikipedia · en.wikipedia.org
- AppLovin (APP) Company Profile & Description - Stock Analysis · stockanalysis.com
- IONOS Group SE (ETR:IOS) Company Profile & Description · stockanalysis.com
- GigSky — Funding, Investors & Team | Seedtable · seedtable.com
- Iphone Os CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Is Apple iOS patched? Security status & safe version | IsItPatched · www.isitpatched.com
- CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
Open questions: Current patch status for CVE-2020-3118 and CVE-2022-20821 · Specific remediation steps taken for NOSi container exposure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:51:18.148067+00:00