LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-3118: Cisco IOS XR Software Discovery Protocol Format String Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-3118 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with…

CVE-2020-3118 is a format string vulnerability in Cisco IOS XR Software’s handling of Cisco Discovery Protocol (CDP) messages. An unauthenticated attacker on an adjacent network segment who can send crafted CDP traffic may be able to execute code with administrative privileges or force a device reload. For operators running IOS XR on routers and related infrastructure, this matters because CDP is often enabled by default on local links and a successful attack can take down or fully compromise a network device.

Public detail is limited to the vendor and CISA descriptions; confirm exact affected releases, fixed images, and any platform-specific notes directly against Cisco’s advisory before acting.

How it works

The weakness is CWE-134: use of externally supplied strings in a format-string context without proper validation. Cisco IOS XR improperly validates string input from certain fields in CDP messages. An adjacent attacker who can inject malicious CDP frames can supply crafted format strings that the device processes unsafely. Depending on how the input is handled, that can lead to arbitrary code execution at administrative privilege or to a crash and reload of the affected process or device.

No exploit mechanics beyond that class of abuse are provided in the given facts. Attackers need Layer-2 adjacency (or equivalent reachability to CDP-speaking interfaces); remote Internet exposure is not implied by the summary. Treat any claim of specific payloads or reliable weaponization as unverified unless confirmed in the vendor advisory or your own lab analysis.

Am I affected? How to find it in your systems

Cisco IOS XR typically runs on service-provider and large-enterprise routing platforms (edge, core, aggregation, and some data-center roles). Inventory every device that speaks CDP and runs IOS XR.

If you cannot map a device to a fixed release with certainty, treat it as potentially affected until the advisory confirms otherwise.

How to remediate

Patch first. Apply the updates Cisco published for this vulnerability, following the vendor’s install and reload guidance for your platform and release train. CISA’s required action is to apply updates per vendor instructions.

Document the change and retain evidence of the advisory version you applied for audit and incident response.

If you can't patch immediately

Use compensating controls until the vendor update is installed.

These steps reduce likelihood and impact; they are not a substitute for the vendor fix.

If your data may have been exposed

Actively exploited network-device vulnerabilities can lead to full device compromise, traffic interception, or lateral movement, which in turn can expose credentials and data. Known ransomware use is not documented for this CVE in the provided facts. If you have indicators of exploitation or unauthorized access, follow your incident-response process: isolate affected devices, preserve logs and images, rotate credentials that traversed the device, and assess downstream systems. As a routine check, you can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS XR
WeaknessCWE-134
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities