Zero-day vulnerability in Cisco IOS XR

Resource exhaustion
CVE-2020-3569

Not patched

On August 31 Cisco has updated the original advisory to indicate the second vulnerability exploited in the wild.

Vulnerability details

Advisory: SB2020082902 - Denial of service in Cisco IOS XR Software

Vulnerable component: Cisco IOS XR

CVE-ID: CVE-2020-3569

CVSSv3 score: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:H/RL:U/RC:C

CWE-ID: CWE-400 - Uncontrolled Resource Consumption ('Resource Exhaustion')

Description:

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient queue management for Internet Group Management Protocol (IGMP) packets in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco┬аIOS XR Software. A remote attacker can trigger resource exhaustion by sending crafted IGMP┬а traffic to the affected device and perform a denial of service (DoS) attack.

Note: this vulnerability is being actively exploited in the wild.