cbcvebase.
CVE-2020-3566
published 2020-08-29

CVE-2020-3566: A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to…

PriorityP180high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
3.63%
88.3th percentile
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_ios_xr_software
ciscoios_xr
ciscoios_xr

Detection & IOCsextracted from sources · hover to see the quote

commandlpts pifib hardware police flow igmp rate <rate>
commandipv4 access-list deny igmp any any dvmrp
  • Check for multicast routing enabled on any interface — devices with active multicast routing interfaces are vulnerable. Run 'show igmp interface'; non-empty output indicates exposure.
  • Monitor for anomalous IGMP traffic volume toward Cisco IOS XR devices; exploitation manifests as IGMP process memory exhaustion or crash, potentially destabilizing interior/exterior routing protocols.
  • Exploitation is unauthenticated and remote; look for high-rate inbound IGMP/DVMRP packets on multicast-enabled interfaces as an exploitation indicator.
  • Track Cisco Bug IDs CSCvr86414 and CSCvv54838 / CSCvv60110 for patch applicability checks in asset management and vulnerability scanning.
  • ·Only Cisco IOS XR devices with multicast routing actively configured on at least one interface are vulnerable; devices without multicast routing enabled are NOT affected.
  • ·The IGMP rate-limiting mitigation reduces exploitation speed but does NOT prevent exploitation; it only increases the time required for a successful attack.
  • ·Cisco confirmed there are no workarounds that fully address these vulnerabilities; only mitigations and software updates (SMUs) are available.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck8.6HIGH
cisa8.6HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.