Cisco today warned of some attacks actively targeting the high-severity vulnerability CVE-2020-3118, which was found to affect many routers running the company's Cisco IOS XR software.
IOS XR Network OS is deployed on various Cisco routers, including the NCS 540 & 560, NCS 5500, 8000, and ASR 9000 routers.

The vulnerability affects third-party white box routers and the following Cisco products if they are running vulnerable versions of Cisco IOS XR software and have the Cisco Discovery protocol enabled (both on at least one interface and globally):
- Services Routers Series ASR 9000
- Carrier Routing System (CRS)
- Router IOS XRv 9000
- (NCS) 540 Series Routers
- (NCS) 560 Series Routers
- (NCS) 1000 Series Routers
- (NCS) 5000 Series Routers
- (NCS) 5500 Series Routers
- (NCS) 6000 Series Routers
The attacks began in October
“In October 2020, the Cisco Product Security Response Team (PSIRT) received reports of some attempts to exploit this vulnerability,” the updated advisory states.
“Cisco recommends that customers upgrade to a stable Cisco IOS XR software release to remediate this vulnerability.”
Today, the US National Security Agency (NSA) also included CVE-2020-3118 among 25 security vulnerabilities currently being targeted or exploited by Chinese state-sponsored threat actors.
Attackers could exploit the vulnerability by sending a malicious Cisco Discovery Protocol packet to devices running a vulnerable IOS XR version.
Successful exploitation could allow attackers to cause a stack overflow that could lead to arbitrary code with administrator privileges on the targeted device.
Fortunately, although this Cisco Discovery Protocol Format String Vulnerability could lead to remote code execution, it can only be exploited by unauthorized attackers in the same “broadcast domain” as the vulnerable devices.
Security updates are available
Cisco patched the CVE-2020-3118 security flaw in February 2020, along with four other serious vulnerabilities discovered by IoT security firm Armis and collectively named CDPwn.
The current status of the releases that come with this vulnerability is shown in the table below (more information about available software updates can be found here).

