CVE-2020-3566
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
⚠ KEVEPSS 3.6%
Description
Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.
How to fix CVE-2020-3566
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2020-3566 being exploited?
Yes — CVE-2020-3566 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.