cbcvebase.
CVE-2020-3258
published 2020-06-03

CVE-2020-3258: Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected…

PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.65%
90.8th percentile
Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute arbitrary code on an affected system or cause an affected system to crash and reload. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_ios_12.2_ez16
ciscoios
ciscoios
ciscoios
ciscoios

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability affects Cisco IOS Software on Cisco 809 and 829 Industrial ISRs and Cisco 1000 Series Connected Grid Routers (CGR1000); detection should focus on these specific platform/software combinations
  • Track Cisco Bug IDs CSCvr12083 and CSCvr46885 for patch status and affected version enumeration on monitored devices
  • ·No workarounds are available for these vulnerabilities; only software updates remediate the issue
  • ·The attack surface includes both unauthenticated remote vectors and authenticated local vectors, meaning both network-facing and local access controls are relevant to exposure

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.