← KEV catalog
CISA known exploited vulnerability

CVE-2020-3118

Cisco IOS XR Software Discovery Protocol Format String Vulnerability

SOURCE FACT

Cisco · IOS XR

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2020-3118

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?