← Back

CVE-2020-3417

nvd nist
Published: Sep 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of trust. This vulnerability is due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set. An attacker could exploit this vulnerability by installing code to a specific directory in the underlying operating system (OS) and setting a specific ROMMON variable. A successful exploit could allow the attacker to execute persistent code on the underlying OS. To exploit this vulnerability, the attacker would need access to the root shell on the device or have physical access to the device.

Affected (98)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
98 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 16.10.1
Version 16.10.1a
Version 16.10.1b
Version 16.10.1c
Version 16.10.1d
Version 16.10.1e
Version 16.10.1f
Version 16.10.1g
Version 16.10.1s
Version 16.10.2
Version 16.10.3
Version 16.11.1
Version 16.11.1a
Version 16.11.1b
Version 16.11.1c
Version 16.11.1s
Version 16.11.2
Version 16.12.1
Version 16.12.1a
Version 16.12.1c
Version 16.12.1s
Version 16.12.1t
Version 16.12.1w
Version 16.12.1x
Version 16.12.1y
Version 16.12.2
Version 16.12.2a
Version 16.12.2s
Version 16.12.2t
Version 16.12.3
Version 16.12.3a
Version 16.6.1
Version 16.6.2
Version 16.6.3
Version 16.6.4
Version 16.6.4a
Version 16.6.4s
Version 16.6.5
Version 16.6.5a
Version 16.6.5b
Version 16.6.6
Version 16.6.7
Version 16.6.7a
Version 16.7.1
Version 16.7.1a
Version 16.7.1b
Version 16.7.2
Version 16.7.3
Version 16.7.4
Version 16.8.1
Version 16.8.1a
Version 16.8.1b
Version 16.8.1c
Version 16.8.1d
Version 16.8.1e
Version 16.8.1s
Version 16.8.2
Version 16.8.3
Version 16.9.1
Version 16.9.1a
Version 16.9.1b
Version 16.9.1c
Version 16.9.1d
Version 16.9.1s
Version 16.9.2
Version 16.9.2a
Version 16.9.2s
Version 16.9.3
Version 16.9.3a
Version 16.9.3h
Version 16.9.3s
Version 16.9.4
Version 16.9.4c
Version 16.9.5
Version 16.9.5f
Version 17.1.1
Version 17.1.1a
Version 17.1.1s
Version 17.1.1t
Version 3.18.0sp
Version 3.18.1asp
Version 3.18.1bsp
Version 3.18.1csp
Version 3.18.1gsp
Version 3.18.1hsp
Version 3.18.1isp
Version 3.18.1sp
Version 3.18.2asp
Version 3.18.2sp
Version 3.18.3asp
Version 3.18.3bsp
Version 3.18.3sp
Version 3.18.4sp
Version 3.18.5sp
Version 3.18.6sp
Version 3.18.7sp
Version 3.18.8asp
Version 3.18.8sp

Timeline

No history available yet.