A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.
Threat-Mapped Scoring
Score: 1.5
Priority: P4 - Informational (Low)
EPSS
Score: 0.18957Percentile:
0.95028
CVSS Scoring
CVSS v3.1 Score: 8.6
Severity: HIGH
KEV is present
Mapped CWE(s)
CWE-400
: Uncontrolled Resource Consumption
CWE-770
: Allocation of Resources Without Limits or Throttling
All CAPEC(s)
CAPEC-125 : Flooding
CAPEC-130 : Excessive Allocation
CAPEC-147 : XML Ping of the Death
CAPEC-197 : Exponential Data Expansion
CAPEC-227 : Sustained Client Engagement
CAPEC-229 : Serialized Data Parameter Blowup
CAPEC-230 : Serialized Data with Nested Payloads
CAPEC-231 : Oversized Serialized Data Payloads
CAPEC-469 : HTTP DoS
CAPEC-482 : TCP Flood
CAPEC-486 : UDP Flood
CAPEC-487 : ICMP Flood
CAPEC-488 : HTTP Flood
CAPEC-489 : SSL Flood
CAPEC-490 : Amplification
CAPEC-491 : Quadratic Data Expansion
CAPEC-492 : Regular Expression Exponential Blowup
CAPEC-493 : SOAP Array Blowup
CAPEC-494 : TCP Fragmentation
CAPEC-495 : UDP Fragmentation
CAPEC-496 : ICMP Fragmentation
CAPEC-528 : XML Flood
CAPEC(s) with Mapped TTPs
CAPEC-125 : Flooding
Mapped TTPs:
CAPEC-130 : Excessive Allocation
Mapped TTPs:
CAPEC-227 : Sustained Client Engagement
Mapped TTPs:
T1499
: Endpoint Denial of Service
CAPEC-469 : HTTP DoS
Mapped TTPs:
CAPEC-482 : TCP Flood
Mapped TTPs:
CAPEC-488 : HTTP Flood
Mapped TTPs:
CAPEC-489 : SSL Flood
Mapped TTPs:
CAPEC-490 : Amplification
Mapped TTPs:
CAPEC-528 : XML Flood
Mapped TTPs:
Mapped ATT&CK TTPs
T1498.001
: Direct Network Flood
Kill Chain: impact
T1499
: Endpoint Denial of Service
Kill Chain: impact
T1499.003
: Application Exhaustion Flood
Kill Chain: impact
T1499
: Endpoint Denial of Service
Kill Chain: impact
T1499.002
: Service Exhaustion Flood
Kill Chain: impact
T1498.001
: Direct Network Flood
Kill Chain: impact
T1499.001
: OS Exhaustion Flood
Kill Chain: impact
T1499.002
: Service Exhaustion Flood
Kill Chain: impact
T1499.002
: Service Exhaustion Flood
Kill Chain: impact
T1499.002
: Service Exhaustion Flood
Kill Chain: impact
T1498.002
: Reflection Amplification
Kill Chain: impact
T1499.002
: Service Exhaustion Flood
Kill Chain: impact
T1498.001
: Direct Network Flood
Kill Chain: impact
Malware
APTs Threat Group Associations
Campaigns
Affected Products
cpe:2.3:o:cisco:ios_xr:6.4.2:*:*:*:*:*:*:*
← Back to Home
BrownCoat Threat Intelligence Platform | 2025 Steve Gray — You Can’t Take the Sky from Me