← Back

CVE-2020-3423

nvd nist
Published: Sep 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the implementation of the Lua interpreter that is integrated in Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code with root privileges on the underlying Linux operating system (OS) of an affected device. The vulnerability is due to insufficient restrictions on Lua function calls within the context of user-supplied Lua scripts. An attacker with valid administrative credentials could exploit this vulnerability by submitting a malicious Lua script. When this file is processed, an exploitable buffer overflow condition could occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying Linux OS of the affected device.

Affected (1)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
1 vulnerable · 25 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
1100 Integrated Services Router
All versions
Cisco
1101 Integrated Services Router
All versions
Cisco
1109 Integrated Services Router
All versions
Cisco
1111x Integrated Services Router
All versions
Cisco
111x Integrated Services Router
All versions
Cisco
1120 Integrated Services Router
All versions
Cisco
1160 Integrated Services Router
All versions
Cisco
4221 Integrated Services Router
All versions
Cisco
4321 Integrated Services Router
All versions
Cisco
4331 Integrated Services Router
All versions
Cisco
4351 Integrated Services Router
All versions
Cisco
4431 Integrated Services Router
All versions
Cisco
4451 X Integrated Services Router
All versions
Cisco
4461 Integrated Services Router
All versions
Cisco
Asr 1001 Hx
All versions
Cisco
Asr 1001 X
All versions
Cisco
Asr 1002 Hx
All versions
Cisco
Asr 1002 X
All versions
Cisco
Asr 1004
All versions
Cisco
Asr 1006
All versions
Cisco
Asr 1006 X
All versions
Cisco
Asr 1009 X
All versions
Cisco
Asr 1013
All versions
Cisco
Cbr 8 Converged Broadband Router
All versions
Cisco
Cloud Services Router 1000v
All versions

Timeline

No history available yet.