8.6

CVE-2020-3569

Warnung

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Xr Version6.1.4
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version6.2.3
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version6.3.3
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version6.4.2
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version6.5.3
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version6.6.2
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version6.6.3
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version7.0.2
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version7.1.2
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version7.1.15
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version < 6.5.2
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 520 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6008 Version-
CiscoIos Xr Version6.1.4
   CiscoCrs Version-
   CiscoCrs-1 16-slot Line Card Chassis Version-
   CiscoCrs-1 16-slot Single-shelf System Version-
   CiscoCrs-1 4-slot Single-shelf System Version-
   CiscoCrs-1 8-slot Line Card Chassis Version-
   CiscoCrs-1 8-slot Single-shelf System Version-
   CiscoCrs-1 Fabric Card Chassis Version-
   CiscoCrs-1 Line Card Chassis (dual) Version-
   CiscoCrs-1 Line Card Chassis (multi) Version-
   CiscoCrs-1 Multishelf System Version-
   CiscoCrs-3 16-slot Single-shelf System Version-
   CiscoCrs-3 4-slot Single-shelf System Version-
   CiscoCrs-3 8-slot Single-shelf System Version-
   CiscoCrs-3 Multishelf System Version-
   CiscoCrs-8/s-b Crs Version-
   CiscoCrs-8/scrs Version-
   CiscoCrs-x Version-
   CiscoCrs-x 16-slot Single-shelf System Version-
   CiscoCrs-x Multishelf System Version-
   CiscoCrs Performance Route Processor Version-
CiscoIos Xr Version6.4.2
   CiscoCrs Version-
   CiscoCrs-1 16-slot Line Card Chassis Version-
   CiscoCrs-1 16-slot Single-shelf System Version-
   CiscoCrs-1 4-slot Single-shelf System Version-
   CiscoCrs-1 8-slot Line Card Chassis Version-
   CiscoCrs-1 8-slot Single-shelf System Version-
   CiscoCrs-1 Fabric Card Chassis Version-
   CiscoCrs-1 Line Card Chassis (dual) Version-
   CiscoCrs-1 Line Card Chassis (multi) Version-
   CiscoCrs-1 Multishelf System Version-
   CiscoCrs-3 16-slot Single-shelf System Version-
   CiscoCrs-3 4-slot Single-shelf System Version-
   CiscoCrs-3 8-slot Single-shelf System Version-
   CiscoCrs-3 Multishelf System Version-
   CiscoCrs-8/s-b Crs Version-
   CiscoCrs-8/scrs Version-
   CiscoCrs-x Version-
   CiscoCrs-x 16-slot Single-shelf System Version-
   CiscoCrs-x Multishelf System Version-
   CiscoCrs Performance Route Processor Version-
CiscoIos Xr Version6.4.3
   CiscoCrs Version-
   CiscoCrs-1 16-slot Line Card Chassis Version-
   CiscoCrs-1 16-slot Single-shelf System Version-
   CiscoCrs-1 4-slot Single-shelf System Version-
   CiscoCrs-1 8-slot Line Card Chassis Version-
   CiscoCrs-1 8-slot Single-shelf System Version-
   CiscoCrs-1 Fabric Card Chassis Version-
   CiscoCrs-1 Line Card Chassis (dual) Version-
   CiscoCrs-1 Line Card Chassis (multi) Version-
   CiscoCrs-1 Multishelf System Version-
   CiscoCrs-3 16-slot Single-shelf System Version-
   CiscoCrs-3 4-slot Single-shelf System Version-
   CiscoCrs-3 8-slot Single-shelf System Version-
   CiscoCrs-3 Multishelf System Version-
   CiscoCrs-8/s-b Crs Version-
   CiscoCrs-8/scrs Version-
   CiscoCrs-x Version-
   CiscoCrs-x 16-slot Single-shelf System Version-
   CiscoCrs-x Multishelf System Version-
   CiscoCrs Performance Route Processor Version-

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Schwachstelle

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.55% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
psirt@cisco.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.