Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 3, 2022

CVE-2020-3118

High
EPSS 0.3%CISA KEV
Cisco/IOS XR

Description

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

EPSS — Exploit Probability

0.3%

Higher than 52.4% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2020-3118

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
0.3%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Nov 3, 2021

Added to KEV

Nov 3, 2021

Remediation Due

May 3, 2022

Affected Product

Cisco

IOS XR

View all Cisco CVEs