#VU47237 Buffer overflow in Cisco Systems, Inc products - CVE-2020-3423
Published: September 24, 2020 / Updated: October 1, 2020
Cisco IOS XE
4000 Series Integrated Services Routers
Cisco ASR 1000 Series Aggregation Services Routers
Cloud Services Router 1000V Series
Integrated Services Virtual Routers
Cisco Systems, Inc
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to insufficient restrictions on Lua function calls within the context of user-supplied Lua scripts. A local administrator can use a specially crafted Lua script, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.