Cisco Patches For Two High Severity Vulnerabilities In Ios Xr Software Cybers Guards
Tracked as CVE-2020-3566 and CVE-2020-3569 and featuring a CVSS score of 8.6, in late August, when Cisco announced that hackers were already targeting them in attacks, the two bugs were made public. In the Distance Vector Multicast Routing Protocol (DVMRP) feature of IOS XR, both problems were found and could be exploited without authentication to trigger the Internet Community Management Protocol (IGMP) mechanism to drain memory and crash processes. The bugs occur because IGMP packets are not adequately treated, Cisco says, which means that designed IGMP traffic may be sent to the affected devices to activate them....