LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-3569: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-3569 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to…

CVE-2020-3569 is a memory exhaustion vulnerability in Cisco IOS XR Software related to how the Distance Vector Multicast Routing Protocol (DVMRP) handles Internet Group Management Protocol (IGMP) packets. An unauthenticated, remote attacker could crash the IGMP process immediately or force it to consume available memory until it crashes, disrupting multicast-related services on affected routers.

For network operators running Cisco IOS XR, this matters because it can cause process instability or denial of service without authentication. Confirm exact impact and fixed releases against the vendor advisory.

How it works

This issue falls under CWE-400 (Uncontrolled Resource Consumption). The software incorrectly handles certain IGMP packets in the DVMRP path. An attacker who can send crafted IGMP traffic to a vulnerable device may trigger the IGMP process to crash outright or to allocate memory until resources are exhausted and the process fails.

No authentication is required. The result is a denial-of-service condition against the IGMP process rather than code execution. Specific packet formats and exploit mechanics are not detailed here; treat any public proof-of-concept claims cautiously and validate behavior only in controlled lab conditions against the vendor’s description.

Am I affected? How to find it in your systems

Cisco IOS XR is commonly deployed on service-provider and large-enterprise routers that handle multicast routing. Inventory all devices running IOS XR, especially those with DVMRP or IGMP features enabled or exposed to untrusted networks.

If public detail on exact vulnerable configurations is limited, treat any IOS XR system that processes IGMP in a DVMRP context as in-scope until the advisory clears it.

How to remediate

Patch first. Apply the updates Cisco provides for this vulnerability, following the vendor instructions referenced in the CISA guidance. Schedule maintenance windows appropriate for production routers and verify the fixed software train after installation.

If you can't patch immediately

Reduce exposure until you can apply the vendor update:

These steps lower risk but do not replace the official software fix.

If your data may have been exposed

This vulnerability is described as a denial-of-service condition against the IGMP process; ransomware use is not documented. Actively exploited network-device flaws can still be a foothold for broader incidents, so verify device integrity, review authentication and configuration changes, and watch for follow-on activity. You can run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal data associated with your team have appeared in unrelated breaches, then force password resets and enable stronger authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS XR
WeaknessCWE-400
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities