8.8

CVE-2020-3234

A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated but low-privileged, local attacker to log in to the Virtual Device Server (VDS) of an affected device by using a set of default credentials. The vulnerability is due to the presence of weak, hard-coded credentials. An attacker could exploit this vulnerability by authenticating to the targeted device and then connecting to VDS through the device’s virtual console by using the static credentials. A successful exploit could allow the attacker to access the Linux shell of VDS as the root user.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Version12.2(60)ez16
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.0(2)sg11a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.3(3)jaa1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.3(3)jpj
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(1)cg
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(2)cg
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m4
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m5
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m6
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m6a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m7
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m8
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m9
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.4(3)m10
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(1)t
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(1)t2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(1)t3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(1)t4
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(2)t
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(2)t1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(2)t2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(2)t3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(2)t4
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m0a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m2a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m4
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m4a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m5
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m6
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m6a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m7
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m8
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m9
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m10
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.5(3)m11
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(1)t
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(1)t0a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(1)t1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(1)t2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(1)t3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(2)t
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(2)t1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(2)t2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(2)t3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m0a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m1b
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m3a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m4
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m5
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m6
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m6a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m6b
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m7
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m8
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.6(3)m9
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m4
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m4a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m4b
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m5
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m6
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.7(3)m7
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m0a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m1
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m2
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m2a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m3
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m3a
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m3b
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m4
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
CiscoIos Version15.8(3)m5
   Cisco1120 Version-
   Cisco1240
   Cisco809
   Cisco829
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.109
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@cisco.com 8.8 2 6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.