cbcvebase.
CVE-2020-3118
published 2020-02-05

CVE-2020-3118: A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary…

PriorityP185high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
11.68%
95.6th percentile
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

Affected

9 ranges
VendorProductVersion rangeFixed in
ciscocisco_ios_xr_software>= unspecified < 6.6.36.6.3
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr>= 6.6.0 < 6.6.126.6.12
ciscoios_xr>= 7.0.0 < 7.0.27.0.2

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit requires the attacker to be Layer 2 adjacent (same broadcast domain) — monitor for unexpected or malformed Cisco Discovery Protocol (CDP) packets on network segments containing IOS XR devices
  • Trigger mechanism is a malicious CDP packet with improper string input in certain fields — inspect CDP message fields for format string specifiers (e.g., %n, %x, %s) or abnormally long string values that could cause a stack overflow
  • Successful exploitation results in a stack overflow leading to arbitrary code execution with administrative privileges or device reload — alert on unexpected IOS XR process crashes or spontaneous reloads on CDP-enabled interfaces
  • Track Cisco bug IDs CSCvr09190 and CSCvr78185 in device logs and TAC cases as indicators of affected software versions
  • ·There are no workarounds available for this vulnerability — the only mitigation is applying vendor-supplied software updates
  • ·Exploitation is limited to unauthenticated attackers who are Layer 2 adjacent; the attack surface is constrained to broadcast domains containing affected Cisco IOS XR devices with CDP enabled

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.