Permissions, Privileges, and Access Controls in Cisco IOS XE - CVE-2020-3425
Published: September 24, 2020 / Updated: October 1, 2020
Vulnerability identifier: #VU47239
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3425
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to insufficient data protection of sensitive information. A remote authenticated attacker can send a specially crafted API call and gain elevated privileges on the target system.
Affected software
Cisco IOS XE
How to mitigate CVE-2020-3425
Install updates from vendor's website.
Cisco IOS XE - addressed in versions Amsterdam 17.1.2, Amsterdam 17.2.1, Amsterdam 17.2.1r, Amsterdam 17.3.1, Fuji 16.9.6, 16.3.11, 16.9.5.99, 16.9.6, 16.12.1s, 16.12.1z, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 17.1.2, 17.2.1, 17.2.1v, 17.2.1EFT, 17.2.1a, 17.2.1r, 17.2.2, 17.3.0.34, 17.3.1, 17.3.1EFT, 17.3.1a, 17.3.2EFT