cbcvebase.
CVE-2020-3198
published 2020-06-03

CVE-2020-3198: Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected…

PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.47%
90.5th percentile
Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute arbitrary code on an affected system or cause an affected system to crash and reload. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

85 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_ios_12.2_ez16
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability affects Cisco IOS Software on Cisco 809 and 829 Industrial ISRs and Cisco 1000 Series CGR1000 routers; monitor these device types for unexpected crashes/reloads or arbitrary code execution indicators
  • Track Cisco Bug IDs CSCvr12083 and CSCvr46885 for patch status and further technical details related to this CVE
  • ·No workarounds are available for these vulnerabilities; only software updates address them
  • ·The vulnerability is exploitable by an unauthenticated remote attacker, meaning no credentials are required for the network-based attack vector; also exploitable by an authenticated local attacker

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.