ZeroHour

CVE-2020-3569

KEVlarge

Unauthenticated IGMP Memory-Exhaustion DoS in Cisco IOS XR (CVE-2020-3569)

CISA: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

CVSS 3.1
8.6 high
EPSS
3%p88
Published
()
KEV added
AI analysis

CVE-2020-3569 is a memory-exhaustion flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR, caused by incorrect handling of IGMP packets. An unauthenticated, remote attacker triggers it by sending crafted IGMP traffic to an affected device, which can immediately crash the IGMP process or drive it to consume available memory until it crashes. Because the exhausted memory is shared, other processes on the router — including interior and exterior routing protocols — can become unstable, making this an availability-only but potentially broad denial-of-service on a core routing device (CVSS 8.6, availability impact high). Any network running Cisco IOS XR, typically on service-provider and large-enterprise routing platforms, is affected; the specific affected and fixed releases are listed in the Cisco advisory. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, and news coverage reports active exploitation of the IOS XR flaws, while no public proof-of-concept is known.

What to do: Apply the fixed Cisco IOS XR software per Cisco's advisory, which is also the required action listed for this CVE in the CISA KEV catalog. As an interim mitigation, restrict or filter untrusted IGMP traffic destined to IOS XR devices (e.g., via ACLs at network edges) and disable DVMRP where it is not needed. Inventory your estate for IOS XR devices with the DVMRP/IGMP feature enabled and prioritize internet- or untrusted-facing routers for patching.

Affected
Cisco IOS XR
Estimated exposure
large≈ tens of thousands of IOS XR routers worldwide (carrier-grade deployments; exact reachable-device count unknown) — IOS XR runs on Cisco's carrier-class service-provider router lines (e.g., ASR/NCS/CRS platforms) deployed at tens of thousands of provider and large-enterprise sites globally, though only devices reachable with untrusted IGMP traffic have…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.

CISA Known Exploited Vulnerability
Affected
Cisco IOS XR
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios xr
Weakness
CWE-400, CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news