ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Issues Patches For 2 High-Severity IOS XR Flaws Under Active Attacks

criticalVulnerability exploited in the wildimportance 60CVE-2020-3566CVE-2020-3569

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3566
Unauthenticated Memory-Exhaustion DoS in Cisco IOS XR (DVMRP/IGMP)

CVE-2020-3566 is a denial-of-service flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software, caused by insufficient queue management for Internet Group Management Protocol (IGMP) packets. An unauthenticated, remote attacker can trigger it simply by sending crafted IGMP traffic to an affected device. Successful exploitation exhausts process memory, which can destabilize other processes on the router — including interior and exterior routing protocols — resulting in loss of availability (CVSS 3.1: 8.6 High, Availability:High, Scope:Changed). Affected are organizations running Cisco IOS XR (carrier-grade platforms such as the ASR 9000, NCS and CRS families) where the DVMRP feature is in use. The flaw is listed in CISA KEV (added 2021-11-03) and news reports describe active exploitation of IOS XR DoS flaws, though no public proof-of-concept code is known.

Do: Apply software updates per Cisco's instructions (Cisco has released, or will release, IOS XR updates that fix this flaw) and verify on each device whether DVMRP is configured and whether IGMP traffic is received from untrusted networks. As interim mitigation, limit or rate-limit IGMP traffic reaching IOS XR devices via ACLs or control-plane policing, and prioritize patching given the CISA KEV listing and reported active exploitation.

8.64% KEV
  • Cisco IOS XR
largeplausibly tens of thousands of IOS XR routers deployed in service-provider and large-enterprise networks (no public install count; the directly…
CVE-2020-3569
Unauthenticated IGMP Memory-Exhaustion DoS in Cisco IOS XR (CVE-2020-3569)

CVE-2020-3569 is a memory-exhaustion flaw in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR, caused by incorrect handling of IGMP packets. An unauthenticated, remote attacker triggers it by sending crafted IGMP traffic to an affected device, which can immediately crash the IGMP process or drive it to consume available memory until it crashes. Because the exhausted memory is shared, other processes on the router — including interior and exterior routing protocols — can become unstable, making this an availability-only but potentially broad denial-of-service on a core routing device (CVSS 8.6, availability impact high). Any network running Cisco IOS XR, typically on service-provider and large-enterprise routing platforms, is affected; the specific affected and fixed releases are listed in the Cisco advisory. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, and news coverage reports active exploitation of the IOS XR flaws, while no public proof-of-concept is known.

Do: Apply the fixed Cisco IOS XR software per Cisco's advisory, which is also the required action listed for this CVE in the CISA KEV catalog. As an interim mitigation, restrict or filter untrusted IGMP traffic destined to IOS XR devices (e.g., via ACLs at network edges) and disable DVMRP where it is not needed. Inventory your estate for IOS XR devices with the DVMRP/IGMP feature enabled and prioritize internet- or untrusted-facing routers for patching.

8.63% KEV
  • Cisco IOS XR
large≈ tens of thousands of IOS XR routers worldwide (carrier-grade deployments; exact reachable-device count unknown)
Full article424 words · extracted from thehackernews.com · click to collapse

Cisco yesterday released security patches for two high-severity vulnerabilities affecting its IOS XR software that were found exploited in the wild a month ago.

Tracked as CVE-2020-3566 and CVE-2020-3569, details for both zero-day unauthenticated DoS vulnerabilities were made public by Cisco late last month when the company found hackers actively exploiting Cisco IOS XR Software that is installed on a range of Cisco's carrier-grade and data center routers.

Both DoS vulnerabilities resided in Cisco IOS XR Software's Distance Vector Multicast Routing Protocol (DVMRP) feature and existed due to incorrect implementation of queue management for Internet Group Management Protocol (IGMP) packets on affected devices.

IGMP is a communication protocol typically used by hosts and adjacent routers to efficiently use resources for multicasting applications when supporting streaming content such as online video streaming and gaming.

"These vulnerabilities affect any Cisco device that is running any release of Cisco IOS XR Software if an active interface is configured under multicast routing and it is receiving DVMRP traffic," Cisco said in an advisory.

"An administrator can determine whether multicast routing is enabled on a device by issuing the show igmp interface command."

Successful exploitation of these vulnerabilities could allow remote unauthenticated hackers to send specially crafted IGMP packets to affected devices to either immediately crash the IGMP process or exhaust process memory and eventually crash.

The memory consumption may negatively result in instability of other processes running on the device, including routing protocols for both internal and external networks.

The vulnerabilities affect all Cisco devices running any release of Cisco IOS XR Software if an active interface is configured under multicast routing, and it is receiving DVMRP traffic.

At the time Cisco initially made these vulnerabilities public, the company provided some mitigation to resolve the issues and block the active exploitation attempts, but now it has finally released Software Maintenance Upgrades (SMUs) to address the vulnerabilities completely.

"Although there are no workarounds for these vulnerabilities, there are multiple mitigations available to customers depending on their needs," the company said.

"When considering mitigations, it should be understood that for the memory exhaustion case, the rate limiter and the access control methods are effective. For the immediate IGMP process crash case, only the access control method is effective."

Cisco customers are highly recommended to make sure they are running the latest Cisco IOS XR Software release earlier than 6.6.3 and Cisco IOS XR Software release 6.6.3 and later.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2020/09/cisco.html