Skip to main content

CVE-2020-3569

8.6
HIGHCVSS v3.1 Base Score
4.69%
LOW RiskEPSS (90th percentile)
KEV

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.

Published: 9/23/2020
Modified: 10/28/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Vendor / Product:

Cisco IOS XR

Required Action:

Apply updates per vendor instructions.

Due Date: 5/3/2022(OVERDUE)
Added to KEV:

11/3/2021

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2020-3569

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CVSS v2 Score

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Score (Exploitation Probability)

4.69%LOW Exploitation Risk
90th percentile

This vulnerability has a 4.69% probability of being exploited in the next 30 days, ranking higher than 90% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-400, CWE-770)

CVE-2026-45498MEDIUM 4

Microsoft Defender Denial of Service Vulnerability

5/20/2026
CVE-2025-68272HIGH 7.5

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue.

1/1/2026
CVE-2025-13836HIGH 7.5

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

12/1/2025
CVE-2025-46556MEDIUM 6.5

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters) due to a lack of server-side validation of note length. Once such a note is added, the activity stream UI fails to render; therefore, new notes cannot be displayed, effectively breaking all future collaboration on the issue. This issue is fixed in version 2.27.2.

11/4/2025
CVE-2025-53521CRITICAL 9.8

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

10/15/2025

Similar SeverityHIGH