PT-2020-1993 · Cisco · Cisco Fxos

Published

2020-02-26

·

Updated

2023-08-15

·

CVE-2020-3166

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco FXOS Software (affected versions not specified)
Description The issue is related to insufficient input validation in the CLI of Cisco FXOS Software, allowing an authenticated, local attacker to read or write arbitrary files on the underlying operating system. An attacker could exploit this by including crafted arguments to a specific CLI command, potentially gaining access to modify, add, or delete data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-01310
CVE-2020-3166

Affected Products

Cisco Fxos