← Back

CVE-2020-3477

nvd nist
Published: Sep 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by using a specific command at the command line. A successful exploit could allow the attacker to obtain read-only access to files that are located on the flash: filesystem that otherwise might not have been accessible.

Affected (1)

Products: Cisco: Ios
1 product
Ios
Configuration A
1 vulnerable · 8 platform
Vulnerable SoftwareAffected Versions
Version 16.3.11
Running on/withPlatform Versions
Cisco
2610xm
All versions
Cisco
2611xm
All versions
Cisco
2612
All versions
Cisco
2620xm
All versions
Cisco
2621xm
All versions
Cisco
2650xm
All versions
Cisco
2651xm
All versions
Cisco
2691
All versions

Timeline

No history available yet.