ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers are exploiting two zero-day flaws in Cisco enterprise-grade routers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3566
Unauthenticated Memory-Exhaustion DoS in Cisco IOS XR (DVMRP/IGMP)

CVE-2020-3566 is a denial-of-service flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software, caused by insufficient queue management for Internet Group Management Protocol (IGMP) packets. An unauthenticated, remote attacker can trigger it simply by sending crafted IGMP traffic to an affected device. Successful exploitation exhausts process memory, which can destabilize other processes on the router — including interior and exterior routing protocols — resulting in loss of availability (CVSS 3.1: 8.6 High, Availability:High, Scope:Changed). Affected are organizations running Cisco IOS XR (carrier-grade platforms such as the ASR 9000, NCS and CRS families) where the DVMRP feature is in use. The flaw is listed in CISA KEV (added 2021-11-03) and news reports describe active exploitation of IOS XR DoS flaws, though no public proof-of-concept code is known.

Do: Apply software updates per Cisco's instructions (Cisco has released, or will release, IOS XR updates that fix this flaw) and verify on each device whether DVMRP is configured and whether IGMP traffic is received from untrusted networks. As interim mitigation, limit or rate-limit IGMP traffic reaching IOS XR devices via ACLs or control-plane policing, and prioritize patching given the CISA KEV listing and reported active exploitation.

8.64% KEV
  • Cisco IOS XR
largeplausibly tens of thousands of IOS XR routers deployed in service-provider and large-enterprise networks (no public install count; the directly…
CVE-2020-3569
Unauthenticated IGMP Memory-Exhaustion DoS in Cisco IOS XR (CVE-2020-3569)

CVE-2020-3569 is a memory-exhaustion flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR, caused by incorrect handling of IGMP packets. An unauthenticated, remote attacker triggers it by sending crafted IGMP traffic to an affected device, which can immediately crash the IGMP process or drive it to consume available memory until it crashes. Because the exhausted memory is shared, other processes on the router — including interior and exterior routing protocols — can become unstable, making this an availability-only but potentially broad denial-of-service on a core routing device (CVSS 8.6, availability impact high). Any network running Cisco IOS XR, typically on service-provider and large-enterprise routing platforms, is affected; the specific affected and fixed releases are listed in the Cisco advisory. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, and news coverage reports active exploitation of the IOS XR flaws, while no public proof-of-concept is known.

Do: Apply the fixed Cisco IOS XR software per Cisco's advisory, which is also the required action listed for this CVE in the CISA KEV catalog. As an interim mitigation, restrict or filter untrusted IGMP traffic destined to IOS XR devices (e.g., via ACLs at network edges) and disable DVMRP where it is not needed. Inventory your estate for IOS XR devices with the DVMRP/IGMP feature enabled and prioritize internet- or untrusted-facing routers for patching.

8.63% KEV
  • Cisco IOS XR
large≈ tens of thousands of IOS XR routers worldwide (carrier-grade deployments; exact reachable-device count unknown)
Full article252 words · extracted from helpnetsecurity.com · click to collapse

A technical support intervention has revealed two zero-day vulnerabilities in the OS running on Cisco enterprise-grade routers that attackers are trying to actively exploit.

zero-day Cisco enterprise routers

Cisco plans to release software updates to plug these security holes, but in the meantime administrators are advised to implement one or all of the provided mitigations.

About the vulnerabilities

The two zero-day flaws – CVE-2020-3566 and CVE-2020-3569 – affect the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software, running on Cisco enterprise-grade routers for service providers, data centers, enterprises, and critical infrastructure.

They can be exploited by an unauthenticated, remote attacker by sending crafted IGMP (Internet Group Management Protocol) traffic to an affected device.

“A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols,” Cisco explained.

Proposed mitigations include:

  • Implementing a rate limiter for IGMP traffic
  • implementing an access control entry (ACE) to an existing interface access control list (ACL). “Alternatively, the customer can create a new ACL for a specific interface that denies DVMRP traffic inbound on that interface,” the company noted.

The company has also provided indicators of compromise, i.e., messages that can be seen in the system logs if a device is experiencing memory exhaustion based on exploitation of these vulnerabilities.

“These vulnerabilities affect any Cisco device that is running any release of Cisco IOS XR Software if an active interface is configured under multicast routing,” they added.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/09/01/zero-day-cisco-enterprise-routers/