ZeroHour

CVE-2020-3566

KEVlarge

Unauthenticated Memory-Exhaustion DoS in Cisco IOS XR (DVMRP/IGMP)

CISA: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

CVSS 3.1
8.6 high
EPSS
4%p89
Published
()
KEV added
AI analysis

CVE-2020-3566 is a denial-of-service flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software, caused by insufficient queue management for Internet Group Management Protocol (IGMP) packets. An unauthenticated, remote attacker can trigger it simply by sending crafted IGMP traffic to an affected device. Successful exploitation exhausts process memory, which can destabilize other processes on the router — including interior and exterior routing protocols — resulting in loss of availability (CVSS 3.1: 8.6 High, Availability:High, Scope:Changed). Affected are organizations running Cisco IOS XR (carrier-grade platforms such as the ASR 9000, NCS and CRS families) where the DVMRP feature is in use. The flaw is listed in CISA KEV (added 2021-11-03) and news reports describe active exploitation of IOS XR DoS flaws, though no public proof-of-concept code is known.

What to do: Apply software updates per Cisco's instructions (Cisco has released, or will release, IOS XR updates that fix this flaw) and verify on each device whether DVMRP is configured and whether IGMP traffic is received from untrusted networks. As interim mitigation, limit or rate-limit IGMP traffic reaching IOS XR devices via ACLs or control-plane policing, and prioritize patching given the CISA KEV listing and reported active exploitation.

Affected
Cisco IOS XR
Estimated exposure
largeplausibly tens of thousands of IOS XR routers deployed in service-provider and large-enterprise networks (no public install count; the directly… — No published install counts exist, so this order of magnitude is estimated from IOS XR's role as the OS for widely deployed carrier-router platforms (ASR 9000/NCS/CRS) used by hundreds of ISPs and large enterprises, with far fewer devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.

CISA Known Exploited Vulnerability
Affected
Cisco IOS XR
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios xr
Weakness
CWE-400, CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news