Imechapishwa: Sep 02, 2020 15:42
Advisory No:
Source:
Software Affected:
Cisco has issued a security advisory on multiple vulnerabilities on any CISCO device running IOS XR Software. These vulnerabilities tracked as CVE-2020-3566 affected Distance Vector Multicast Routing Protocol (DVMRP) feature and could allow an unauthenticated, remote attacker to exhaust process memory of an affected device.
Advisory No: TZCERT/SA/2020/09/02 Date of First Release: 2nd September, 2020 Source: CISCO Software Affected: Any Cisco device with an active interface configured with multicast routing and running Cisco IOS XR software. Overview: Cisco has issued a security advisory on multiple vulnerabilities on any CISCO device running IOS XR Software. These vulnerabilities tracked as CVE-2020-3566 affected Distance Vector Multicast Routing Protocol (DVMRP) feature and could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. Description: These vulnerabilities are caused by inadequate queue management for packets in the Internet Group Management Protocol (IGMP).The attacker could take advantage of these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit may allow the remote attacker to cause memory exhaustion, that may result in instability of other processes running on the device. Impact: Successful exploitation of the vulnerability could allow an adversary to exhaust process memory of an affected device. Solution: Cisco has not yet identified any workarounds for this vulnerability; however, there are multiple mitigations available;
Successful exploitation of the vulnerability could allow an adversary to exhaust process memory of an affected device.
Cisco has not yet identified any workarounds for this vulnerability; however, there are multiple mitigations available; First, determine whether Multicast Routing is enabled on your router. An administrator can issue the show igmp interface If the output of the command is empty then multicast routing is not enabled, and the device is not affected by these vulnerabilities, however, if the command shows the following output then multicast routing is enabled:
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.