← Vulnerability feed

Vulnerability record · CVE-2020-3566 · published 29 August 2020

CVE-2020-3566: Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustion

Cisco · Ios Xr

Cisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated remote attacker can send crafted IGMP traffic to exhaust process memory and destabilize the device. The flaw is rated CVSS 8.6 (HIGH) and is listed in CISA's Known Exploited Vulnerabilities catalog.

8.6 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 3.7% · top 10.7% CWE-400 · Uncontrolled resource consumptionCWE-770 · Allocation without limits
8.6CVSS 3.1 base score, v2 7.8
3.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.6 with network reachability, no authentication, and confirmed inclusion in CISA KEV make this a high-priority patching target despite the availability-only impact.

What it is

Cisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated remote attacker can send crafted IGMP traffic to exhaust process memory and destabilize the device. The flaw is rated CVSS 8.6 (HIGH) and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

The attacker can exhaust process memory, causing instability in other processes including interior and exterior routing protocols. This degrades or disrupts routing on the affected device; the record does not indicate code execution or data disclosure.

Attack surface

Reachable over the network via crafted IGMP traffic to an affected device running DVMRP; the CVSS vector shows no privileges and no user interaction required. DVMRP must be enabled for the vulnerable code path to be exposed.

Exploitation

CVE-2020-3566 is in CISA KEV (added 2021-11-03), indicating known exploitation, though no ransomware campaign use is documented. EPSS 30-day probability is 0.037 (89th percentile), and references are vendor advisory and US government resources only.

What to do

  • Apply the Cisco IOS XR software updates referenced in the vendor advisory cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz.
  • If DVMRP is not required, disable it to remove the vulnerable code path.
  • Restrict IGMP and multicast traffic to trusted network segments using ACLs or infrastructure ACLs.
  • Monitor device memory and process stability for signs of exhaustion and failover if degradation occurs.
  • Track CISA KEV remediation due date (2022-05-03) and confirm patched status across the fleet.

Detection

  • Alert on sustained memory growth or process restarts on IOS XR devices with DVMRP enabled.
  • Monitor for abnormal volumes or malformed IGMP packets reaching routing devices.
  • Log and review DVMRP/IGMP configuration changes and unexpected multicast traffic sources.
  • Correlate device instability events with routing protocol process failures (interior and exterior).

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3566 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3566 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-3118Cisco IOS XR CDP packet parsing flaw allows adjacent code executionCisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overfl…KEVEPSS 12%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.6CVE-2020-3569Cisco IOS XR DVMRP IGMP packet handling memory exhaustionCisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash th…KEVEPSS 3.3%analysed8.0CVE-2018-0175Cisco IOS, IOS XE and IOS XR LLDP format string flawA format string vulnerability exists in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.5%analysed7.5CVE-2016-6415Cisco IOS IKEv1 memory disclosure via SA negotiationThe IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker…KEVEPSS 88%analysed7.5CVE-2010-3035Cisco IOS XR BGP peering reset via unrecognized transitive attributeCisco IOS XR 3.4.0 through 3.9.1 mishandles unrecognized transitive BGP attributes when BGP is enabled, allowing a crafted prefix announcement to res…KEVEPSS 5.7%analysed6.5CVE-2022-20821Cisco IOS XR health check RPM exposes Redis port without authenticationThe health check RPM in Cisco IOS XR Software opens TCP port 6379 by default when activated, exposing the Redis instance inside the NOSi container. A…KEVEPSS 11%analysed5.9CVE-2009-2055Cisco IOS XR BGP invalid attribute causes session reset DoSCisco IOS XR 3.4.0 through 3.8.1 fails to properly validate a BGP UPDATE message attribute, allowing a remote peer to reset BGP sessions. Because BGP…KEVEPSS 3.3%analysed

Source: NIST National Vulnerability Database (record CVE-2020-3566), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.