On August 31 Cisco has updated the original advisory to indicate the second vulnerability exploited in the wild.
Vulnerable component: Cisco IOS XR
CVSSv3 score: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:H/RL:U/RC:C
CWE-ID: CWE-400 - Uncontrolled Resource Consumption ('Resource Exhaustion')
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient queue management for Internet Group Management Protocol (IGMP) packets in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco┬аIOS XR Software. A remote attacker can trigger resource exhaustion by sending crafted IGMP┬а traffic to the affected device and perform a denial of service (DoS) attack.Note: this vulnerability is being actively exploited in the wild.