CVE-2020-3118
Cisco IOS XR Software Discovery Protocol Format String Vulnerability
⚠ KEVEPSS 11.7%
Description
Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.
How to fix CVE-2020-3118
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2020-3118 being exploited?
Yes — CVE-2020-3118 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.