CVE-2020-3216
published 2020-06-03CVE-2020-3216: A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the…
PriorityP433medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.44%
35.2th percentile
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication mechanisms for certain commands. An attacker could exploit this vulnerability by stopping the boot initialization of an affected device. A successful exploit could allow the attacker to bypass authentication and gain unrestricted access to the root shell of the affected device.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_sd-wan_software | — | — |
| cisco | ios_xe_sd-wan | — | — |
| cisco | ios_xe_sd-wan | — | — |
| cisco | ios_xe_sd-wan | — | — |
| cisco | ios_xe_sd-wan | — | — |
| cisco | ios_xe_sd-wan | — | — |
| cisco | ios_xe_sd-wan | — | — |
| cisco | ios_xe_sd-wan | — | — |
| cisco | ios_xe_sd-wan | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE SD-WAN Software Authentication Bypass Vulnerability
vendor_cisco·2020-06-03·CVSS 6.8
CVE-2020-3216 [MEDIUM] CWE-287 Cisco IOS XE SD-WAN Software Authentication Bypass Vulnerability
Cisco IOS XE SD-WAN Software Authentication Bypass Vulnerability
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device.
The vulnerability exists because the affected software has insufficient authentication mechanisms for certain commands. An attacker could exploit this vulnerability by stopping the boot initialization of an affected device. A successful exploit could allow the attacker to bypass authentication and gain unrestricted access to the root shell of the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following lin
Cisco
Cisco IOS XE SD-WAN Software Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3216 Cisco IOS XE SD-WAN Software Authentication Bypass Vulnerability
CVE-2020-3216: Cisco IOS XE SD-WAN Software Authentication Bypass Vulnerability
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication mechanisms for certain commands. An attacker could exploit this vulnerability by stopping the boot initialization of an affected device. A successful exploit could allow the attacker to bypass authentication and gain unrestricted access to the root shell of the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-287, CWE-287
Bug IDs: CSCvk38480
GHSA
GHSA-vx84-h8r2-7438: A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted acces
ghsa_unreviewed·2022-05-24
CVE-2020-3216 [HIGH] CWE-287 GHSA-vx84-h8r2-7438: A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted acces
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication mechanisms for certain commands. An attacker could exploit this vulnerability by stopping the boot initialization of an affected device. A successful exploit could allow the attacker to bypass authentication and gain unrestricted access to the root shell of the affected device.
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id ASCII
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id ASCII"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005162; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UPDATE
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UPDATE"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005163; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id SELECT
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id SELECT"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005158; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id INSERT
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id INSERT"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005160; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UNION SELECT
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UNION SELECT"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005159; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mi
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id DELETE
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id DELETE"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005161; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique
No public exploits indexed.
Bugzilla
CVE-2020-14311 grub2: Integer overflow in grub_ext2_read_link leads to heap-based buffer overflow
bugzilla·2020-06-29·CVSS 5.7
CVE-2020-14311 [MEDIUM] CVE-2020-14311 grub2: Integer overflow in grub_ext2_read_link leads to heap-based buffer overflow
CVE-2020-14311 grub2: Integer overflow in grub_ext2_read_link leads to heap-based buffer overflow
Integer overflow in grub_ext2_read_link triggered by a specially crafted ext4 filesystem containing a symlink inode with a size of UINT32_MAX, which leads to a zero-sized allocation and subsequent heap buffer overflow with attacker controlled data.
Discussion:
Acknowledgments:
Name: Chris Coulson (Ubuntu Security Team)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:3216 https://access.redhat.com/errata/RHSA-2020:3216
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-14311
---
This issue has been addressed in the following pr
Bugzilla
CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
bugzilla·2020-06-29·CVSS 6.7
CVE-2020-14309 [MEDIUM] CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
Integer overflow in grub_squash_read_symlink triggered by a specially crafted squashfs filesystem containing a symlink inode with a name length of UINT32, which leads to a zero-sized allocation and subsequent heap buffer overflow with attacker controlled data.
Discussion:
Acknowledgments:
Name: Chris Coulson (Ubuntu Security Team)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:3216 https://access.redhat.com/errata/RHSA-2020:3216
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-14309
---
This issue has been addressed
Bugzilla
CVE-2020-14310 grub2: Integer overflow read_section_as_string may lead to heap-based buffer overflow
bugzilla·2020-06-29·CVSS 5.7
CVE-2020-14310 [MEDIUM] CVE-2020-14310 grub2: Integer overflow read_section_as_string may lead to heap-based buffer overflow
CVE-2020-14310 grub2: Integer overflow read_section_as_string may lead to heap-based buffer overflow
Integer overflow in read_section_as_string triggered by a specially crafted font file containing a NAME section with a length of UINT32_MAX, which leads to a zero-sized allocation and subsequent heap buffer overflow with attacker controlled data.
Discussion:
Acknowledgments:
Name: Chris Coulson (Ubuntu Security Team)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:3216 https://access.redhat.com/errata/RHSA-2020:3216
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-14310
---
This issue has been addressed in the following p
2020-06-03
Published