Vulnerability record · CVE-2020-3566 · published 29 August 2020
CVE-2020-3566: Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustion
Cisco · Ios Xr
Cisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated remote attacker can send crafted IGMP traffic to exhaust process memory and destabilize the device. The flaw is rated CVSS 8.6 (HIGH) and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Automated analysis
high priorityCVSS 8.6 with network reachability, no authentication, and confirmed inclusion in CISA KEV make this a high-priority patching target despite the availability-only impact.
What it is
Cisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated remote attacker can send crafted IGMP traffic to exhaust process memory and destabilize the device. The flaw is rated CVSS 8.6 (HIGH) and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
The attacker can exhaust process memory, causing instability in other processes including interior and exterior routing protocols. This degrades or disrupts routing on the affected device; the record does not indicate code execution or data disclosure.
Attack surface
Reachable over the network via crafted IGMP traffic to an affected device running DVMRP; the CVSS vector shows no privileges and no user interaction required. DVMRP must be enabled for the vulnerable code path to be exposed.
Exploitation
CVE-2020-3566 is in CISA KEV (added 2021-11-03), indicating known exploitation, though no ransomware campaign use is documented. EPSS 30-day probability is 0.037 (89th percentile), and references are vendor advisory and US government resources only.
What to do
- Apply the Cisco IOS XR software updates referenced in the vendor advisory cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz.
- If DVMRP is not required, disable it to remove the vulnerable code path.
- Restrict IGMP and multicast traffic to trusted network segments using ACLs or infrastructure ACLs.
- Monitor device memory and process stability for signs of exhaustion and failover if degradation occurs.
- Track CISA KEV remediation due date (2022-05-03) and confirm patched status across the fleet.
Detection
- Alert on sustained memory growth or process restarts on IOS XR devices with DVMRP enabled.
- Monitor for abnormal volumes or malformed IGMP packets reaching routing devices.
- Log and review DVMRP/IGMP configuration changes and unexpected multicast traffic sources.
- Correlate device instability events with routing protocol process failures (interior and exterior).
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3566 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-3566 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3566), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.