← Vulnerability feed

Vulnerability record · CVE-2020-3118 · published 5 February 2020

CVE-2020-3118: Cisco IOS XR CDP packet parsing flaw allows adjacent code execution

Cisco · Ios Xr

Cisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overflow. An unauthenticated attacker on the same Layer 2 broadcast domain can send a crafted CDP packet to execute code or reload the device.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 12% · top 4.1% CWE-134 · CWE-134CWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 8.3
12%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8 with adjacent unauthenticated code execution and confirmed exploitation in CISA KEV, though it requires Layer 2 adjacency.

What it is

Cisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overflow. An unauthenticated attacker on the same Layer 2 broadcast domain can send a crafted CDP packet to execute code or reload the device.

Impact

A successful exploit can run arbitrary code with administrative privileges on the affected device or force a reload, giving the attacker full control of the router or causing a denial of service.

Attack surface

Reached over Layer 2 via crafted Cisco Discovery Protocol packets; the attacker must be in the same broadcast domain as the target. No authentication or user interaction is required (CVSS vector AV:A/PR:N/UI:N).

Exploitation

CVE-2020-3118 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and EPSS shows a 30-day probability of about 11.7% (95.8th percentile). No public exploit code or ransomware use is documented in this record.

What to do

  • Apply the Cisco IOS XR software updates referenced in the vendor advisory cisco-sa-20200205-iosxr-cdp-rce.
  • If CDP is not required, disable it on affected interfaces to remove the attack path.
  • Restrict Layer 2 adjacency on access ports and use port security or similar controls to limit who can send CDP frames.
  • Segment management and user networks so untrusted hosts are not in the same broadcast domain as IOS XR devices.
  • Track CISA KEV remediation due date (2022-05-03) and verify patched status across the fleet.

Detection

  • Monitor for unexpected or malformed CDP frames on interfaces facing untrusted segments.
  • Alert on device reloads or crashes on IOS XR devices with no planned maintenance cause.
  • Review IOS XR logs and crashinfo for stack overflow or CDP parsing faults.
  • Baseline CDP neighbor tables and flag new or spoofed CDP advertisements from unexpected sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3118 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IOS XR Software Discovery Protocol Format String Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3118 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.6CVE-2020-3569Cisco IOS XR DVMRP IGMP packet handling memory exhaustionCisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash th…KEVEPSS 3.3%analysed8.6CVE-2020-3566Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustionCisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated…KEVEPSS 3.7%analysed8.0CVE-2018-0175Cisco IOS, IOS XE and IOS XR LLDP format string flawA format string vulnerability exists in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.5%analysed7.5CVE-2016-6415Cisco IOS IKEv1 memory disclosure via SA negotiationThe IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker…KEVEPSS 88%analysed7.5CVE-2010-3035Cisco IOS XR BGP peering reset via unrecognized transitive attributeCisco IOS XR 3.4.0 through 3.9.1 mishandles unrecognized transitive BGP attributes when BGP is enabled, allowing a crafted prefix announcement to res…KEVEPSS 5.7%analysed6.5CVE-2022-20821Cisco IOS XR health check RPM exposes Redis port without authenticationThe health check RPM in Cisco IOS XR Software opens TCP port 6379 by default when activated, exposing the Redis instance inside the NOSi container. A…KEVEPSS 11%analysed5.9CVE-2009-2055Cisco IOS XR BGP invalid attribute causes session reset DoSCisco IOS XR 3.4.0 through 3.8.1 fails to properly validate a BGP UPDATE message attribute, allowing a remote peer to reset BGP sessions. Because BGP…KEVEPSS 3.3%analysed

Source: NIST National Vulnerability Database (record CVE-2020-3118), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.