ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Issues Warning Over IOS XR Zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2020-3566

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3566
Unauthenticated Memory-Exhaustion DoS in Cisco IOS XR (DVMRP/IGMP)

CVE-2020-3566 is a denial-of-service flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software, caused by insufficient queue management for Internet Group Management Protocol (IGMP) packets. An unauthenticated, remote attacker can trigger it simply by sending crafted IGMP traffic to an affected device. Successful exploitation exhausts process memory, which can destabilize other processes on the router — including interior and exterior routing protocols — resulting in loss of availability (CVSS 3.1: 8.6 High, Availability:High, Scope:Changed). Affected are organizations running Cisco IOS XR (carrier-grade platforms such as the ASR 9000, NCS and CRS families) where the DVMRP feature is in use. The flaw is listed in CISA KEV (added 2021-11-03) and news reports describe active exploitation of IOS XR DoS flaws, though no public proof-of-concept code is known.

Do: Apply software updates per Cisco's instructions (Cisco has released, or will release, IOS XR updates that fix this flaw) and verify on each device whether DVMRP is configured and whether IGMP traffic is received from untrusted networks. As interim mitigation, limit or rate-limit IGMP traffic reaching IOS XR devices via ACLs or control-plane policing, and prioritize patching given the CISA KEV listing and reported active exploitation.

8.64% KEV
  • Cisco IOS XR
largeplausibly tens of thousands of IOS XR routers deployed in service-provider and large-enterprise networks (no public install count; the directly…
Full article417 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 01, 2020

Cisco has warned of an active zero-day vulnerability in its router software that's being exploited in the wild and could allow a remote, authenticated attacker to carry out memory exhaustion attacks on an affected device.

"An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device," Cisco said in an advisory posted over the weekend.

"A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols."

Although the company said it will release software fixes to address the flaw, it did not share a timeline for when it plans to make it available. The networking equipment maker said it became aware of attempts to exploit the flaw on August 28.

Tracked as CVE-2020-3566, the severity of the vulnerability has been rated "high" with a Common Vulnerability Scoring System score of 8.6 out of a maximum 10.

The bug affects all Cisco gear running its Internetwork Operating System (IOS) XR Software and stems from an issue in the Distance Vector Multicast Routing Protocol (DVMRP) feature that makes it possible for an adversary to send specially crafted Internet Group Management Protocol (IGMP) packets to the susceptible device in question and exhaust process memory.

IGMP is typically used to efficiently use resources for multicasting applications when supporting streaming content such as online video streaming and gaming. The flaw lies in the manner IOS XR Software queues these packets, potentially causing memory exhaustion and disruption of other processes.

While there are no workarounds to resolve the issue, Cisco recommends administrators to run the "show igmp interface" command to determine if multicast routing is enabled.

"If the output of 'show igmp interface' is empty, multicast routing is not enabled and the device is not affected by these vulnerabilities," the company said.

Additionally, admins can also check the system logs for signs of memory exhaustion and implement rate-limiting to reduce IGMP traffic rates to mitigate the risk.

Cisco didn't elaborate on how the attackers were exploiting this vulnerability and with what goal in mind.

But given that resource exhaustion attacks are also a form of denial-of-service attacks, it wouldn't be surprising if bad actors are leveraging the flaw to interfere with the regular functioning of the system.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2020/09/cisco-issue-warning-over-ios-xr-zero.html