Permissions, Privileges, and Access Controls in Cisco IOS XE - CVE-2020-3425

 

Permissions, Privileges, and Access Controls in Cisco IOS XE - CVE-2020-3425

Published: September 24, 2020 / Updated: October 1, 2020


Vulnerability identifier: #VU47239
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3425
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to insufficient data protection of sensitive information. A remote authenticated attacker can send a specially crafted API call and gain elevated privileges on the target system.


Affected software

Cisco IOS XE

How to mitigate CVE-2020-3425

Install updates from vendor's website.

Cisco IOS XE - addressed in versions Amsterdam 17.1.2, Amsterdam 17.2.1, Amsterdam 17.2.1r, Amsterdam 17.3.1, Fuji 16.9.6, 16.3.11, 16.9.5.99, 16.9.6, 16.12.1s, 16.12.1z, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 17.1.2, 17.2.1, 17.2.1v, 17.2.1EFT, 17.2.1a, 17.2.1r, 17.2.2, 17.3.0.34, 17.3.1, 17.3.1EFT, 17.3.1a, 17.3.2EFT

External References

Related Security Bulletins