CVE-2020-3403OS Command Injection in Cisco IOS XE Software

Severity
7.8HIGHNVD
EPSS
0.1%
top 73.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateMay 24

Description

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating system that will execute with root privileges upon the next reboot of the device. The authenticated user must have privileged EXEC permissions on the device. The vulnerability is due to insufficient protection of values passed to a script that executes during device startup. An attacker could exploit this vulnerability by writing values to a specific fi

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDcisco/ios_xe17.2.1

🔴Vulnerability Details

2
GHSA
GHSA-jwvq-qvwv-pjcm: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating syste2022-05-24
CVEList
Cisco IOS XE Software Command Injection Vulnerability2020-09-24

📋Vendor Advisories

1
Cisco
Cisco IOS XE Software Command Injection Vulnerability2020-09-24
CVE-2020-3403 — OS Command Injection in Cisco | cvebase