7.2
CVE-2020-3216
- EPSS 0.09%
- Published 03.06.2020 18:15:19
- Last modified 21.11.2024 05:30:34
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication mechanisms for certain commands. An attacker could exploit this vulnerability by stopping the boot initialization of an affected device. A successful exploit could allow the attacker to bypass authentication and gain unrestricted access to the root shell of the affected device.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Ios Xe Sd-wan Version16.9.0
Cisco ≫ Ios Xe Sd-wan Version16.9.1
Cisco ≫ Ios Xe Sd-wan Version16.9.2
Cisco ≫ Ios Xe Sd-wan Version16.9.3
Cisco ≫ Ios Xe Sd-wan Version16.9.4
Cisco ≫ Ios Xe Sd-wan Version16.10.0
Cisco ≫ Ios Xe Sd-wan Version16.10.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.229 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
psirt@cisco.com | 6.8 | 0.9 | 5.9 |
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.