PT-2020-4175 · Cisco · Cisco Ios Xe

Victor Kamensky

+1

·

Published

2020-09-24

·

Updated

2020-10-08

·

CVE-2020-3513

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed (affected versions not specified)
Description: The issue is related to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set, allowing an authenticated, local attacker with high privileges to execute persistent code at bootup and break the chain of trust. An attacker could exploit this by copying a specific file to the local file system of an affected device and defining specific ROMMON variables, potentially allowing the attacker to run arbitrary code on the underlying operating system (OS) with root privileges. To exploit, an attacker would need to have access to the root shell on the device or have physical access to the device.
Recommendations: For Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed, update to a version that includes the software updates released by Cisco to address these vulnerabilities. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04597
CVE-2020-3513

Affected Products

Cisco Ios Xe