← Back

CVE-2020-3569

nvd nist
Published: Sep 23, 2020Modified: Oct 28, 2025CISA KEV

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.

Affected (12)

Products: Cisco: Ios Xr
1 product
Ios Xr
Configuration A
8 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 6.2.3
Version 6.3.3
Version 6.5.3
Version 6.6.2
Version 6.6.3
Version 7.0.2
Version 7.1.15
Version 7.1.2
Running on/withPlatform Versions
Cisco
Asr 9000v
All versions
Cisco
Asr 9001
All versions
Cisco
Asr 9006
All versions
Cisco
Asr 9010
All versions
Cisco
Asr 9901
All versions
Cisco
Asr 9903
All versions
Cisco
Asr 9904
All versions
Cisco
Asr 9906
All versions
Cisco
Asr 9910
All versions
Cisco
Asr 9912
All versions
Cisco
Asr 9922
All versions
Configuration B
1 vulnerable · 13 platform
Vulnerable SoftwareAffected Versions
Before 6.5.2
Running on/withPlatform Versions
Cisco
Ncs 5001
All versions
Cisco
Ncs 5002
All versions
Cisco
Ncs 5011
All versions
Cisco
Ncs 520
All versions
Cisco
Ncs 540
All versions
Cisco
Ncs 5501
All versions
Cisco
Ncs 5501
Version se
Cisco
Ncs 5502
All versions
Cisco
Ncs 5502
Version se
Cisco
Ncs 5508
All versions
Cisco
Ncs 5516
All versions
Cisco
Ncs 560
All versions
Cisco
Ncs 6008
All versions
Configuration C
3 vulnerable · 20 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 6.1.4
Version 6.4.2
Version 6.4.3
Running on/withPlatform Versions
Cisco
Crs
All versions
Cisco
Crs 1 16 Slot Line Card Chassis
All versions
Cisco
Crs 1 16 Slot Single Shelf System
All versions
Cisco
Crs 1 4 Slot Single Shelf System
All versions
Cisco
Crs 1 8 Slot Line Card Chassis
All versions
Cisco
Crs 1 8 Slot Single Shelf System
All versions
Cisco
Crs 1 Fabric Card Chassis
All versions
Cisco
Crs 1 Line Card Chassis (dual)
All versions
Cisco
Crs 1 Line Card Chassis (multi)
All versions
Cisco
Crs 1 Multishelf System
All versions
Cisco
Crs 3 16 Slot Single Shelf System
All versions
Cisco
Crs 3 4 Slot Single Shelf System
All versions
Cisco
Crs 3 8 Slot Single Shelf System
All versions
Cisco
Crs 3 Multishelf System
All versions
Cisco
Crs 8/s B Crs
All versions
Cisco
Crs 8/scrs
All versions
Cisco
Crs X
All versions
Cisco
Crs X 16 Slot Single Shelf System
All versions
Cisco
Crs X Multishelf System
All versions
Cisco
Crs Performance Route Processor
All versions

Timeline

No history available yet.