CVE-2020-3569
KEVlargeUnauthenticated IGMP Memory-Exhaustion DoS in Cisco IOS XR (CVE-2020-3569)
CISA: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
CVE-2020-3569 is a memory-exhaustion flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR, caused by incorrect handling of IGMP packets. An unauthenticated, remote attacker triggers it by sending crafted IGMP traffic to an affected device, which can immediately crash the IGMP process or drive it to consume available memory until it crashes. Because the exhausted memory is shared, other processes on the router — including interior and exterior routing protocols — can become unstable, making this an availability-only but potentially broad denial-of-service on a core routing device (CVSS 8.6, availability impact high). Any network running Cisco IOS XR, typically on service-provider and large-enterprise routing platforms, is affected; the specific affected and fixed releases are listed in the Cisco advisory. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, and news coverage reports active exploitation of the IOS XR flaws, while no public proof-of-concept is known.
What to do: Apply the fixed Cisco IOS XR software per Cisco's advisory, which is also the required action listed for this CVE in the CISA KEV catalog. As an interim mitigation, restrict or filter untrusted IGMP traffic destined to IOS XR devices (e.g., via ACLs at network edges) and disable DVMRP where it is not needed. Inventory your estate for IOS XR devices with the DVMRP/IGMP feature enabled and prioritize internet- or untrusted-facing routers for patching.
| Cisco IOS XR | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.
- Affected
- Cisco IOS XR
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios xr
- Weakness
- CWE-400, CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H