Skip to main content

CVE-2020-3566

8.6
HIGHCVSS v3.1 Base Score
2.14%
LOW RiskEPSS (85th percentile)
KEV

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.

Published: 8/29/2020
Modified: 10/28/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Vendor / Product:

Cisco IOS XR

Required Action:

Apply updates per vendor instructions.

Due Date: 5/3/2022(OVERDUE)
Added to KEV:

11/3/2021

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2020-3566

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CVSS v2 Score

7.8

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Score (Exploitation Probability)

2.14%LOW Exploitation Risk
85th percentile

This vulnerability has a 2.14% probability of being exploited in the next 30 days, ranking higher than 85% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-400)

CVE-2026-45498MEDIUM 4

Microsoft Defender Denial of Service Vulnerability

5/20/2026
CVE-2025-68272HIGH 7.5

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue.

1/1/2026
CVE-2025-13836HIGH 7.5

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

12/1/2025
CVE-2024-8892MEDIUM 5.3

Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.

9/18/2024
CVE-2024-6036CRITICAL 9.1

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`. This unrestricted server restart capability can severely disrupt service availability, cause data loss or corruption, and potentially compromise system integrity.

7/10/2024

Similar SeverityHIGH