cbcvebase.
CVE-2020-3284
published 2020-11-06

CVE-2020-3284: A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote…

PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.77%
84.6th percentile
A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned code during the PXE boot process on an affected device. The PXE boot loader is part of the BIOS and runs over the management interface of hardware platforms that are running Cisco IOS XR Software only. The vulnerability exists because internal commands that are issued when the PXE network boot process is loading a software image are not properly verified. An attacker could exploit this vulnerability by compromising the PXE boot server and replacing a valid software image with a malicious one. Alternatively, the attacker could impersonate the PXE boot server and send a PXE boot reply with a malicious file. A successful exploit could allow the attacker to execute unsigned code on the affected device. Note: To fix this vulnerability, both the Cisco IOS XR Software and the BIOS must be upgraded. The BIOS code is included in Cisco IOS XR Software but might require additional installation steps. For further information, see the Fixed Software section of this advisory.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoa99-rp2-se_firmware< 14.3514.35
ciscoa99-rp2-tr_firmware< 14.3514.35
ciscoa99-rp3-se_firmware< 30.2330.23
ciscoa99-rp3-tr_firmware< 30.2330.23
ciscoa99-rsp-se_firmware< 16.1416.14
ciscoa99-rsp-tr_firmware< 16.1416.14
ciscoa9k-rsp5-se_firmware< 31.2031.20
ciscoa9k-rsp5-tr_firmware< 31.2031.20
ciscoa9k-rsp880-lt-se_firmware< 17.3417.34
ciscoa9k-rsp880-lt-tr_firmware< 17.3417.34
ciscoa9k-rsp880-se_firmware< 10.6510.65
ciscoa9k-rsp880-tr_firmware< 10.6510.65
ciscoasr-9901-rp_firmware< 22.2022.20
ciscocisco_ios_xr_software
ciscoios_xr< 6.5.26.5.2
ciscoios_xr< 7.2.17.2.1
ciscoios_xr< 6.6.256.6.25
ciscoios_xr< 1.211.21
ciscoios_xr< 1.121.12
ciscoios_xr
ciscoios_xr>= 7.0.0 < 7.0.27.0.2
ciscon540-12z20g-sys-a_d_firmware< 1.151.15
ciscon540-24z8q2c-m_firmware< 1.151.15
ciscon540-28z4c-sys-a_d_firmware< 1.151.15
ciscon540-acc-sys_firmware< 1.151.15

Detection & IOCsextracted from sources · hover to see the quote

  • Attacker may impersonate the PXE boot server and send a malicious PXE boot reply over the management interface — monitor for rogue DHCP/PXE (UDP port 67/68/69/4011) responses on the management network segment of Cisco IOS XR 64-bit hardware platforms.
  • Attacker vector requires compromising or impersonating the PXE boot server to replace a valid software image — alert on unexpected TFTP (UDP 69) file transfers originating from non-authorised servers toward Cisco IOS XR management interfaces during boot.
  • Exploitation is limited to the management interface — restrict and monitor Layer-2/Layer-3 access to the out-of-band management network for all Cisco IOS XR 64-bit hardware platforms to reduce attack surface.
  • Both Cisco IOS XR Software AND the BIOS component must be upgraded to remediate; track Cisco Bug IDs CSCvi82550, CSCvq23340, and CSCvq31064 for patch status and verify BIOS upgrade completion on affected devices.
  • ·No workarounds exist for this vulnerability; the only mitigation is patching both IOS XR Software and the BIOS.
  • ·The BIOS upgrade is not automatic — it is bundled in IOS XR Software but may require explicit additional installation steps; devices may remain vulnerable even after an IOS XR software upgrade if the BIOS step is skipped.
  • ·Vulnerability is only exploitable during the PXE network boot process — devices not configured to PXE-boot over the network are not exposed during normal operation, but exposure exists whenever a device is rebooted and PXE is the active boot method.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.