← Back

CVE-2020-3213

nvd nist
Published: Jun 3, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to those of the root user of the underlying operating system. The vulnerability is due to the ROMMON allowing for special parameters to be passed to the device at initial boot up. An attacker could exploit this vulnerability by sending parameters to the device at initial boot up. An exploit could allow the attacker to elevate from a Priv15 user to the root user and execute arbitrary commands with the privileges of the root user.

Affected (192)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
192 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 16.1.1
Version 16.1.2
Version 16.1.3
Version 16.10.1
Version 16.10.1a
Version 16.10.1b
Version 16.10.1e
Version 16.10.1s
Version 16.10.2
Version 16.11.1
Version 16.11.1a
Version 16.11.1b
Version 16.11.1c
Version 16.11.1s
Version 16.11.2
Version 16.12.1
Version 16.12.1a
Version 16.12.1c
Version 16.12.1s
Version 16.12.1t
Version 16.2.1
Version 16.2.2
Version 16.3.1
Version 16.3.1a
Version 16.3.2
Version 16.3.3
Version 16.3.4
Version 16.3.5
Version 16.3.5b
Version 16.3.6
Version 16.3.7
Version 16.3.8
Version 16.3.9
Version 16.4.1
Version 16.4.2
Version 16.4.3
Version 16.5.1
Version 16.5.1a
Version 16.5.1b
Version 16.5.2
Version 16.5.3
Version 16.6.1
Version 16.6.2
Version 16.6.3
Version 16.6.4
Version 16.6.4a
Version 16.6.4s
Version 16.6.5
Version 16.6.5a
Version 16.6.5b
Version 16.6.6
Version 16.6.7
Version 16.6.7a
Version 16.7.1
Version 16.7.2
Version 16.7.3
Version 16.8.1
Version 16.8.1a
Version 16.8.1b
Version 16.8.1c
Version 16.8.1s
Version 16.8.2
Version 16.8.3
Version 16.9.1
Version 16.9.1a
Version 16.9.1b
Version 16.9.1c
Version 16.9.1d
Version 16.9.1s
Version 16.9.2
Version 16.9.2a
Version 16.9.2s
Version 16.9.3
Version 16.9.3a
Version 16.9.3h
Version 16.9.3s
Version 16.9.4
Version 16.9.4c
Version 3.10.0s
Version 3.10.10s
Version 3.10.1s
Version 3.10.2as
Version 3.10.2s
Version 3.10.2ts
Version 3.10.3s
Version 3.10.4s
Version 3.10.5s
Version 3.10.6s
Version 3.10.7s
Version 3.10.8as
Version 3.10.8s
Version 3.10.9s
Version 3.11.0s
Version 3.11.1s
Version 3.11.2s
Version 3.11.3s
Version 3.11.4s
Version 3.12.0as
Version 3.12.0s
Version 3.12.1s
Version 3.12.2s
Version 3.12.3s
Version 3.12.4s
Version 3.13.0as
Version 3.13.0s
Version 3.13.10s
Version 3.13.1s
Version 3.13.2as
Version 3.13.2s
Version 3.13.3s
Version 3.13.4s
Version 3.13.5as
Version 3.13.5s
Version 3.13.6as
Version 3.13.6bs
Version 3.13.6s
Version 3.13.7as
Version 3.13.7s
Version 3.13.8s
Version 3.13.9s
Version 3.14.0s
Version 3.14.1s
Version 3.14.2s
Version 3.14.3s
Version 3.14.4s
Version 3.15.0s
Version 3.15.1cs
Version 3.15.1s
Version 3.15.2s
Version 3.15.3s
Version 3.15.4s
Version 3.16.0as
Version 3.16.0bs
Version 3.16.0cs
Version 3.16.0s
Version 3.16.10s
Version 3.16.1as
Version 3.16.2as
Version 3.16.2bs
Version 3.16.2s
Version 3.16.3as
Version 3.16.3s
Version 3.16.4as
Version 3.16.4bs
Version 3.16.4cs
Version 3.16.4ds
Version 3.16.4es
Version 3.16.4gs
Version 3.16.4s
Version 3.16.5as
Version 3.16.5bs
Version 3.16.5s
Version 3.16.6bs
Version 3.16.6s
Version 3.16.7as
Version 3.16.7bs
Version 3.16.7s
Version 3.16.8s
Version 3.16.9s
Version 3.17.0s
Version 3.17.1as
Version 3.17.1s
Version 3.17.2s
Version 3.17.3s
Version 3.17.4s
Version 3.18.0s
Version 3.18.0sp
Version 3.18.1bsp
Version 3.18.1csp
Version 3.18.1gsp
Version 3.18.1hsp
Version 3.18.1isp
Version 3.18.1s
Version 3.18.1sp
Version 3.18.2s
Version 3.18.2sp
Version 3.18.3s
Version 3.18.3sp
Version 3.18.4s
Version 3.18.4sp
Version 3.18.5sp
Version 3.18.6sp
Version 3.18.7sp
Version 3.18.8sp
Version 3.8.0s
Version 3.8.1s
Version 3.8.2s
Version 3.9.0as
Version 3.9.0s
Version 3.9.1as
Version 3.9.1s
Version 3.9.2s

Related CWEs

Timeline

No history available yet.