target entity

IOS XR

6 source-linked records in the current knowledge graph.

high

CVE-2022-20821: Cisco IOS XR Open Port Vulnerability

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container. Required action: Apply updates per vendor instructions.

CVE-2022-20821EPSS 11.8%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3118: Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device. Required action: Apply updates per vendor instructions.

CVE-2020-3118EPSS 11.7%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3566: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. Required action: Apply updates per vendor instructions.

CVE-2020-3566EPSS 3.6%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3569: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. Required action: Apply updates per vendor instructions.

CVE-2020-3569EPSS 3.3%CiscoIOS XR
CISA KEV ↗ · unattributed attribution