Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3257


Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.


Published

2020-06-03T18:15:21.840

Last Modified

2024-11-21T05:30:40.277

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 15.8\(3.0z\)m1 Yes
Operating System cisco ios 15.9 Yes
Hardware cisco 1120_connected_grid_router - No
Hardware cisco 1240_connected_grid_router - No
Hardware cisco ir809g-lte-ga-k9 - No
Hardware cisco ir809g-lte-la-k9 - No
Hardware cisco ir809g-lte-na-k9 - No
Hardware cisco ir809g-lte-vz-k9 - No
Hardware cisco ir829-2lte-ea-ak9 - No
Hardware cisco ir829-2lte-ea-bk9 - No
Hardware cisco ir829-2lte-ea-ek9 - No
Hardware cisco ir829gw-lte-ga-ck9 - No
Hardware cisco ir829gw-lte-ga-ek9 - No
Hardware cisco ir829gw-lte-ga-sk9 - No
Hardware cisco ir829gw-lte-ga-zk9 - No
Hardware cisco ir829gw-lte-na-ak9 - No
Hardware cisco ir829gw-lte-vz-ak9 - No

References