#VU47238 Permissions, Privileges, and Access Controls in Cisco IOS XE - CVE-2020-3141
Published: September 24, 2020 / Updated: October 1, 2020
Cisco IOS XE
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to a lack of input and validation checking mechanisms for certain HTTP requests to APIs on an affected device. A remote authenticated attacker can send a specially crafted HTTP request and execute CLI commands or configuration changes as if they were an administrative user.