CVE-2020-3118

Cisco IOS XR: Software Discovery Protocol Format String

As of , CVE-2020-3118 in Cisco IOS XR is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 3 November 2021
US federal deadline
3 May 2022181 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.12Higher than 95% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

CISA's description

A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

The CVE record's description, from cisco

CVE published
5 February 2020
Assigned by
cisco
CVSS
8.8 High (CVSS 3.0, from the CNA)
CWE-134
Use of Externally-Controlled Format String
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

IOS XR: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2022-20821Open PortCisco IOS XRPatch soon0.11
CVE-2010-3035Border Gateway Protocol (BGP) Denial-of-ServiceCisco IOS XRPatch soon0.06
CVE-2020-3566Software DVMRP Memory ExhaustionCisco IOS XRPatch soon0.04
CVE-2009-2055Border Gateway Protocol (BGP) Denial-of-ServiceCisco IOS XRPatch soon0.03
CVE-2020-3569Software DVMRP Memory ExhaustionCisco IOS XRPatch soon0.03

Read further