PT-2020-2896 · Cisco · Cisco Ios Xe Sd-Wan

Published

2020-06-03

·

Updated

2020-06-10

·

CVE-2020-3216

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE SD-WAN Software (affected versions not specified)
Description A vulnerability exists due to insufficient authentication mechanisms for certain commands, allowing an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The issue can be exploited by stopping the boot initialization of the device, potentially giving the attacker full control over the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03053
CVE-2020-3216

Affected Products

Cisco Ios Xe Sd-Wan