CVE-2020-3118 is a format string vulnerability in the Cisco Discovery Protocol (CDP) implementation of Cisco IOS XR Software. The flaw is caused by improper validation of string input from certain fields in received CDP messages. A remote attacker who is unauthenticated but Layer 2 adjacent can send a crafted malicious CDP packet to a vulnerable device, triggering a stack overflow condition in the CDP processing path. Successful exploitation can result in arbitrary code execution with administrative privileges on the affected device, or can cause the device to reload. Affected platforms include Cisco IOS XR-based products such as ASR 9000 Series Aggregation Services Routers, Carrier Routing System (CRS), IOS XRv 9000 Router, and NCS 540/560/1000/5000/5500/6000 Series routers.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A format string vulnerability in Cisco IOS XR Software related to Cisco Discovery Protocol (CDP).
A Cisco Discovery Protocol format string vulnerability in Cisco IOS XR Software affecting multiple router platforms.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.