Cisco warns that threat actors are attempting to exploit a high severity DoS flaw in its Cisco IOS XR software that runs on carrier-grade routers.

Cisco warned over the weekend that attackers are trying to exploit a high severity memory exhaustion denial-of-service (DoS) vulnerability (CVE-2020-3566) affecting the Cisco IOS XR Network OS that runs on carrier-grade routers.

Cisco IOS XR Network OS currently run on multiple router families, including NCS 540 & 560, NCS 5500, 8000, and ASR 9000 series routers.

This flaw affects any Cisco device that is running any release of Cisco IOS XR Software if an active interface is configured under multicast routing.

The bad news is that the vulnerability has yet to be addressed by Cisco, at the time of writing the company issued a security advisory that includes mitigation.

“A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device.” reads the advisory.

“On August 28, 2020, the Cisco Product Security Incident Response Team (PSIRT) became aware of attempted exploitation of this vulnerability in the wild.” 

The vulnerability is caused by insufficient queue management for Internet Group Management Protocol (IGMP) packets, it could be exploited by an attacker by sending crafted IGMP traffic to a vulnerable device.

A successful attack could cause memory exhaustion, resulting in instability of other processes, including interior and exterior routing protocols.

The advisory recommends users to run the show igmp interface command to determine if multicast routing is enabled on their device.

Running the command on IOS XR routers were multicast routing is not enabled will produce an empty output.

 The following output shows a device with multicast routing enabled:

The advisory states that there are multiple mitigations available to customers depending on their needs, for example, implementing a rate limiter to reduce the traffic rate and increase the time necessary for successful exploitation.

“This will require that customers understand their current rate of IGMP traffic and set a rate lower than the current average rate.” continues the advisory. “In configuration mode, the customer can enter the lpts pifib hardware police flow igmp rate command as follows:

This command will not remove the exploit vector.”

Users can also implement an access control entry (ACE) to an existing interface access control list (ACL) or a new ACL to deny inbound DVRMP traffic to interfaces with multicast routing enabled.

Cisco also recommends disabling IGMP routing for an interface where processing IGMP traffic is not necessary by entering IGMP router configuration mode.