← Back

CVE-2020-3207

nvd nist
Published: Jun 3, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. This vulnerability is due to insufficient input validation checks while processing boot options. An attacker could exploit this vulnerability by modifying device boot options to execute attacker-provided code. A successful exploit may allow an attacker to bypass the Secure Boot process and execute malicious code on an affected device with root-level privileges.

Affected (19)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
19 vulnerable · 55 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 16.10.1
Version 16.10.1e
Version 16.10.1s
Version 16.11.1
Version 16.11.1a
Version 16.11.1b
Version 16.11.1c
Version 16.11.1s
Version 16.12.1
Version 16.12.1c
Version 16.12.1s
Version 16.9.2
Version 16.9.2a
Version 16.9.2s
Version 16.9.3
Version 16.9.3a
Version 16.9.3h
Version 16.9.3s
Version 16.9.4
Running on/withPlatform Versions
Cisco
Catalyst 3650 12x48uq
All versions
Cisco
Catalyst 3650 12x48ur
All versions
Cisco
Catalyst 3650 12x48uz
All versions
Cisco
Catalyst 3650 24pd
All versions
Cisco
Catalyst 3650 24pdm
All versions
Cisco
Catalyst 3650 48fq
All versions
Cisco
Catalyst 3650 48fqm
All versions
Cisco
Catalyst 3650 8x24uq
All versions
Cisco
Catalyst 3850 24xs
All versions
Cisco
Catalyst 3850 48xs
All versions
Cisco
Catalyst 3850 Nm 2 40g
All versions
Cisco
Catalyst 3850 Nm 8 10g
All versions
Cisco
Catalyst C9200 24p
All versions
Cisco
Catalyst C9200 24t
All versions
Cisco
Catalyst C9200 48p
All versions
Cisco
Catalyst C9200 48t
All versions
Cisco
Catalyst C9200l 24p 4g
All versions
Cisco
Catalyst C9200l 24p 4x
All versions
Cisco
Catalyst C9200l 24pxg 2y
All versions
Cisco
Catalyst C9200l 24pxg 4x
All versions
Cisco
Catalyst C9200l 24t 4g
All versions
Cisco
Catalyst C9200l 24t 4x
All versions
Cisco
Catalyst C9200l 48p 4g
All versions
Cisco
Catalyst C9200l 48p 4x
All versions
Cisco
Catalyst C9200l 48pxg 2y
All versions
Cisco
Catalyst C9200l 48pxg 4x
All versions
Cisco
Catalyst C9200l 48t 4g
All versions
Cisco
Catalyst C9200l 48t 4x
All versions
Cisco
Catalyst C9300 24p
All versions
Cisco
Catalyst C9300 24s
All versions
Cisco
Catalyst C9300 24t
All versions
Cisco
Catalyst C9300 24u
All versions
Cisco
Catalyst C9300 24ux
All versions
Cisco
Catalyst C9300 48p
All versions
Cisco
Catalyst C9300 48s
All versions
Cisco
Catalyst C9300 48t
All versions
Cisco
Catalyst C9300 48u
All versions
Cisco
Catalyst C9300 48un
All versions
Cisco
Catalyst C9300 48uxm
All versions
Cisco
Catalyst C9300l 24p 4g
All versions
Cisco
Catalyst C9300l 24p 4x
All versions
Cisco
Catalyst C9300l 24t 4g
All versions
Cisco
Catalyst C9300l 24t 4x
All versions
Cisco
Catalyst C9300l 48p 4g
All versions
Cisco
Catalyst C9300l 48p 4x
All versions
Cisco
Catalyst C9300l 48t 4g
All versions
Cisco
Catalyst C9300l 48t 4x
All versions
Cisco
Catalyst C9500 12q
All versions
Cisco
Catalyst C9500 16x
All versions
Cisco
Catalyst C9500 24q
All versions
Cisco
Catalyst C9500 24y4c
All versions
Cisco
Catalyst C9500 32c
All versions
Cisco
Catalyst C9500 32qc
All versions
Cisco
Catalyst C9500 40x
All versions
Cisco
Catalyst C9500 48y4c
All versions

Timeline

No history available yet.