CVE-2020-3566 is a critical vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software, affecting various ASR 9000 series routers. An unauthenticated, remote attacker can exploit insufficient queue management for IGMP packets by sending crafted traffic, leading to memory exhaustion and instability of critical processes. With a CVSS score of 8.6 (HIGH) and a FAUCET Risk Score of 99/100, this vulnerability has a severe impact on availability. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog and extensive media coverage, despite a lack of public exploit code in Metasploit or ExploitDB. The vulnerability has garnered significant community discussion, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.4.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:6.4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.