A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2020-3118

Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Published
2021-11-03
Modified
2026-07-31
Sources
cisa-kev

Summary

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.