PT-2020-4183 · Cisco · Cisco Ios Xe Rom Monitor (Rommon)
Published
2020-09-24
·
Updated
2023-05-22
·
CVE-2020-3524
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cisco ASR 920 Series Aggregation Services Routers, Cisco ASR 1000 Series Aggregation Services Routers, and Cisco cBR-8 Converged Broadband Routers (affected versions not specified)
Description:
A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software could allow an unauthenticated, physical attacker to break the chain of trust and load a compromised software image on an affected device. The issue is due to the presence of a debugging configuration option in the affected software. An attacker could exploit this by connecting to the device through the console, forcing it into ROMMON mode, and writing a malicious pattern using that specific option. A successful exploit could allow the attacker to break the chain of trust and load a compromised software image, which is any software image not digitally signed by Cisco.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios Xe Rom Monitor (Rommon)