logo
Home/CVEs/CVE-2020-3118/

CVE-2020-3118 - Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Project:Cisco

Product:IOS XR

Date Added:2021-11-03Due Date:2022-05-03

Vulnerability Name

Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Description

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-3118