CVE-2020-3566
KEVlargeUnauthenticated Memory-Exhaustion DoS in Cisco IOS XR (DVMRP/IGMP)
CISA: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
CVE-2020-3566 is a denial-of-service flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software, caused by insufficient queue management for Internet Group Management Protocol (IGMP) packets. An unauthenticated, remote attacker can trigger it simply by sending crafted IGMP traffic to an affected device. Successful exploitation exhausts process memory, which can destabilize other processes on the router — including interior and exterior routing protocols — resulting in loss of availability (CVSS 3.1: 8.6 High, Availability:High, Scope:Changed). Affected are organizations running Cisco IOS XR (carrier-grade platforms such as the ASR 9000, NCS and CRS families) where the DVMRP feature is in use. The flaw is listed in CISA KEV (added 2021-11-03) and news reports describe active exploitation of IOS XR DoS flaws, though no public proof-of-concept code is known.
What to do: Apply software updates per Cisco's instructions (Cisco has released, or will release, IOS XR updates that fix this flaw) and verify on each device whether DVMRP is configured and whether IGMP traffic is received from untrusted networks. As interim mitigation, limit or rate-limit IGMP traffic reaching IOS XR devices via ACLs or control-plane policing, and prioritize patching given the CISA KEV listing and reported active exploitation.
| Cisco IOS XR | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.
- Affected
- Cisco IOS XR
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios xr
- Weakness
- CWE-400, CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H