Buffer overflow in Cisco Systems, Inc products - CVE-2020-3423

 

Buffer overflow in Cisco Systems, Inc products - CVE-2020-3423

Published: September 24, 2020 / Updated: October 1, 2020


Vulnerability identifier: #VU47237
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3423
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to insufficient restrictions on Lua function calls within the context of user-supplied Lua scripts. A local administrator can use a specially crafted Lua script, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

4000 Series Integrated Services Routers
Cisco ASR 1000 Series Aggregation Services Routers
Cloud Services Router 1000V Series
Integrated Services Virtual Routers
Cisco IOS XE

How to mitigate CVE-2020-3423

Install updates from vendor's website.

Cisco IOS XE - addressed in versions Amsterdam 17.1.2, Amsterdam 17.2.1, Amsterdam 17.2.1r, Amsterdam 17.3.1, Fuji 16.9.6, Gibraltar 16.12.4, 15.6.2 SP8a, 16.3.11, 16.9.5.111, 16.9.6, 16.12.1z, 16.12.3s, 16.12.3.20, 16.12.4, 16.12.4a, 17.1.2, 17.2.1, 17.2.1v, 17.2.1EFT, 17.2.1r, 17.2.2, 17.3.0.36, 17.3.1, 17.3.1a, 17.3.2EFT

External References

Related Security Bulletins