CISA Known Exploited Vulnerability

CVE-2020-3569

Cisco · IOS XR

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Date added
BOD 22-01 due date
CWE CWE-400
Ransomware Unknown

CISA description

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

Required action

Apply updates per vendor instructions.