CISA Known Exploited Vulnerability

CVE-2020-3118

Cisco · IOS XR

Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Date added
BOD 22-01 due date
CWE CWE-134
Ransomware Unknown

CISA description

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

Required action

Apply updates per vendor instructions.