10

CVE-2020-3258

Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute arbitrary code on an affected system or cause an affected system to crash and reload. For more information about these vulnerabilities, see the Details section of this advisory.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Version15.8(3)m2
   Cisco1120 Version-
   Cisco1240 Version-
   CiscoIr809g-lte-ga-k9 Version-
   CiscoIr809g-lte-la-k9 Version-
   CiscoIr809g-lte-na-k9 Version-
   CiscoIr809g-lte-vz-k9 Version-
   CiscoIr829-2lte-ea-ak9 Version-
   CiscoIr829-2lte-ea-bk9 Version-
   CiscoIr829-2lte-ea-ek9 Version-
   CiscoIr829gw-lte-ga-ck9 Version-
   CiscoIr829gw-lte-ga-ek9 Version-
   CiscoIr829gw-lte-ga-sk9 Version-
   CiscoIr829gw-lte-ga-zk9 Version-
   CiscoIr829gw-lte-na-ak9 Version-
   CiscoIr829gw-lte-vz-ak9 Version-
CiscoIos Version15.8(9)
   Cisco1120 Version-
   Cisco1240 Version-
   CiscoIr809g-lte-ga-k9 Version-
   CiscoIr809g-lte-la-k9 Version-
   CiscoIr809g-lte-na-k9 Version-
   CiscoIr809g-lte-vz-k9 Version-
   CiscoIr829-2lte-ea-ak9 Version-
   CiscoIr829-2lte-ea-bk9 Version-
   CiscoIr829-2lte-ea-ek9 Version-
   CiscoIr829gw-lte-ga-ck9 Version-
   CiscoIr829gw-lte-ga-ek9 Version-
   CiscoIr829gw-lte-ga-sk9 Version-
   CiscoIr829gw-lte-ga-zk9 Version-
   CiscoIr829gw-lte-na-ak9 Version-
   CiscoIr829gw-lte-vz-ak9 Version-
CiscoIos Version15.9
   Cisco1120 Version-
   Cisco1240 Version-
   CiscoIr809g-lte-ga-k9 Version-
   CiscoIr809g-lte-la-k9 Version-
   CiscoIr809g-lte-na-k9 Version-
   CiscoIr809g-lte-vz-k9 Version-
   CiscoIr829-2lte-ea-ak9 Version-
   CiscoIr829-2lte-ea-bk9 Version-
   CiscoIr829-2lte-ea-ek9 Version-
   CiscoIr829gw-lte-ga-ck9 Version-
   CiscoIr829gw-lte-ga-ek9 Version-
   CiscoIr829gw-lte-ga-sk9 Version-
   CiscoIr829gw-lte-ga-zk9 Version-
   CiscoIr829gw-lte-na-ak9 Version-
   CiscoIr829gw-lte-vz-ak9 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 33.8% 0.965
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
psirt@cisco.com 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.