CVE-2020-3118
KEVmassFormat String Vulnerability in Cisco IOS XR Discovery Protocol Allows Adjacent RCE
CISA: Cisco IOS XR Software Discovery Protocol Format String Vulnerability
CVE-2020-3118 is a format string vulnerability (CWE-134) in the Cisco Discovery Protocol (CDP) implementation of Cisco IOS XR Software, caused by improper validation of string input from certain fields in CDP messages. An unauthenticated attacker who is Layer 2 adjacent (on the same broadcast domain) can trigger it by sending a malicious CDP packet to an affected device, causing a stack overflow (CWE-787). A successful exploit allows the attacker to execute arbitrary code with administrative privileges on the device, or alternatively to cause a device reload (denial of service). Any organization running Cisco IOS XR — typically service-provider and large-enterprise core, edge, and aggregation routers — is affected whenever CDP is enabled on interfaces reachable by an attacker at Layer 2. The flaw is listed in the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, with no public PoC identified and an EPSS estimate of 11.7% (96th percentile) for exploitation within 30 days.
What to do: Apply updates to affected Cisco IOS XR devices per Cisco's advisory, as required by the CISA KEV catalog. As interim mitigation, disable Cisco Discovery Protocol on interfaces connected to untrusted Layer 2 segments or restrict broadcast-domain access to trusted devices. Prioritize IOS XR devices where untrusted users, partners, or shared infrastructure exist on the same VLAN or broadcast domain, since exploitation requires only L2 adjacency.
| cisco ios xr | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
- Affected
- Cisco IOS XR
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios xr
- Weakness
- CWE-134, CWE-787
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H