CVE-2020-3118 is a critical vulnerability in the Cisco Discovery Protocol (CDP) implementation for Cisco IOS XR Software, affecting various Cisco devices. This flaw allows an unauthenticated, adjacent attacker to execute arbitrary code or cause a device reload due to improper validation of string input in CDP messages. With a CVSS score of 8.8 (HIGH), exploitation requires Layer 2 adjacency and can lead to full administrative compromise. This vulnerability has been actively exploited in the wild, as confirmed by its presence in the KEV catalog and NSA advisories, despite a lack of public exploit code on platforms like Metasploit or ExploitDB. The high FAUCET Risk Score of 98/100 and extensive community discussion (18 mentions) underscore its significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.6.0, < 6.6.12CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* | ||
6.5.3CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:6.5.3:*:*:*:*:*:*:* | ||
5.2.5CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:5.2.5:*:*:*:*:*:*:* | ||
6.4.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:6.4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.