Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 3, 2022

CVE-2020-3569

High
EPSS 5.6%CISA KEV
Cisco/IOS XR

Description

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

EPSS — Exploit Probability

5.6%

Higher than 90.1% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2020-3569

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
5.6%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Nov 3, 2021

Added to KEV

Nov 3, 2021

Remediation Due

May 3, 2022

Affected Product

Cisco

IOS XR

View all Cisco CVEs