Vulnerability record · CVE-2020-3118 · published 5 February 2020
CVE-2020-3118: Cisco IOS XR CDP packet parsing flaw allows adjacent code execution
Cisco · Ios Xr
Cisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overflow. An unauthenticated attacker on the same Layer 2 broadcast domain can send a crafted CDP packet to execute code or reload the device.
Description
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with adjacent unauthenticated code execution and confirmed exploitation in CISA KEV, though it requires Layer 2 adjacency.
What it is
Cisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overflow. An unauthenticated attacker on the same Layer 2 broadcast domain can send a crafted CDP packet to execute code or reload the device.
Impact
A successful exploit can run arbitrary code with administrative privileges on the affected device or force a reload, giving the attacker full control of the router or causing a denial of service.
Attack surface
Reached over Layer 2 via crafted Cisco Discovery Protocol packets; the attacker must be in the same broadcast domain as the target. No authentication or user interaction is required (CVSS vector AV:A/PR:N/UI:N).
Exploitation
CVE-2020-3118 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and EPSS shows a 30-day probability of about 11.7% (95.8th percentile). No public exploit code or ransomware use is documented in this record.
What to do
- Apply the Cisco IOS XR software updates referenced in the vendor advisory cisco-sa-20200205-iosxr-cdp-rce.
- If CDP is not required, disable it on affected interfaces to remove the attack path.
- Restrict Layer 2 adjacency on access ports and use port security or similar controls to limit who can send CDP frames.
- Segment management and user networks so untrusted hosts are not in the same broadcast domain as IOS XR devices.
- Track CISA KEV remediation due date (2022-05-03) and verify patched status across the fleet.
Detection
- Monitor for unexpected or malformed CDP frames on interfaces facing untrusted segments.
- Alert on device reloads or crashes on IOS XR devices with no planned maintenance cause.
- Review IOS XR logs and crashinfo for stack overflow or CDP parsing faults.
- Baseline CDP neighbor tables and flag new or spoofed CDP advertisements from unexpected sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3118 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IOS XR Software Discovery Protocol Format String Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.html | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200205-iosxr-cdp-rce | Vendor Advisory |
| http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.html | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200205-iosxr-cdp-rce | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3118 | US Government Resource |
Track CVE-2020-3118 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3118), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.