PT-2020-4176 · Cisco · Cisco Ios Xe

Victor Kamensky

+1

·

Published

2020-09-24

·

Updated

2020-10-07

·

CVE-2020-3416

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed (affected versions not specified)
Description: The issue is related to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set, allowing an authenticated, local attacker with high privileges to execute persistent code at bootup and break the chain of trust. An attacker could exploit this by copying a specific file to the local file system of an affected device and defining specific ROMMON variables, potentially allowing the attacker to run arbitrary code on the underlying operating system (OS) with root privileges. To exploit, an attacker would need to have access to the root shell on the device or have physical access to the device.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04598
CVE-2020-3416

Affected Products

Cisco Ios Xe