CVE-2020-3566
CVE-2020-3566 is a high-severity vulnerability in Cisco Ios Xr with a CVSS 3.x base score of 8.6. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2021-11-03). The underlying weakness is classified as CWE-770.
Key facts
- Severity: High (CVSS 3.x base score 8.6)
- CVSS v2: 7.8
- EPSS exploit prediction: 4% (89th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2021-11-03)
- EU (EUVD) id: EUVD-2020-24837
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2021-11-03)
- Weakness: CWE-770
- Affected product: Cisco Ios Xr
- Published:
- Last modified:
Description
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.
Frequently asked questions
- What is CVE-2020-3566?
- A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.
- How severe is CVE-2020-3566?
- CVE-2020-3566 has a CVSS 3.x base score of 8.6, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2020-3566 being actively exploited?
- Yes. CVE-2020-3566 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2021-11-03, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2020-3566?
- CVE-2020-3566 affects Cisco Ios Xr. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-3566?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2020-3566 have an EU (EUVD) identifier?
- Yes. CVE-2020-3566 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2020-24837. It is also flagged as exploited in the EUVD (since 2021-11-03).
- When was CVE-2020-3566 published?
- CVE-2020-3566 was published on 2020-08-29 and last updated on 2026-06-17.
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3566
Affected products (1)
- cpe:2.3:o:cisco:ios_xr:6.4.2:*:*:*:*:*:*:*
More vulnerabilities in Cisco Ios Xr
- CVE-2026-20274 — Critical (CVSS 9.8): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering…
- CVE-2020-3284 — Critical (CVSS 9.8): A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could…
- CVE-2019-1710 — Critical (CVSS 9.8): A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running…
- CVE-2025-20363 — Critical (CVSS 9.0): A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure…
- CVE-2026-20280 — High (CVSS 8.8): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software…
- CVE-2026-20046 — High (CVSS 8.8): A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an…
All CVEs affecting Cisco Ios Xr →
Other CWE-770 (Allocation of Resources Without Limits or Throttling) vulnerabilities
- CVE-2026-63299 — Critical (CVSS 9.9): An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume…
- CVE-2026-82439 — Critical (CVSS 9.8): Description The DRPC server kept a map from function name to request queue and created an entry the first time…
- CVE-2026-47891 — Critical (CVSS 9.8): A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the…
- CVE-2026-74878 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared…
- CVE-2026-31283 — Critical (CVSS 9.8): In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email…
- CVE-2020-37067 — Critical (CVSS 9.8): Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers…
Browse all CWE-770 (Allocation of Resources Without Limits or Throttling) vulnerabilities →