6
CVE-2020-3503
- EPSS 0.04%
- Published 24.09.2020 18:15:20
- Last modified 19.12.2024 13:52:35
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to insufficient file system permissions on an affected device. An attacker could exploit this vulnerability by connecting to an affected device's guest shell, and accessing or modifying restricted files. A successful exploit could allow the attacker to view or modify restricted information or configurations that are normally not accessible to system administrators.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Ios Xe Version16.12.1
Cisco ≫ 1100-4g Integrated Services Router Version-
Cisco ≫ 1100-4gltegb Integrated Services Router Version-
Cisco ≫ 1100-4gltena Integrated Services Router Version-
Cisco ≫ 1100-4p Integrated Services Router Version-
Cisco ≫ 1100-6g Integrated Services Router Version-
Cisco ≫ 1100-8p Integrated Services Router Version-
Cisco ≫ 1100-lte Integrated Services Router Version-
Cisco ≫ 1100 Integrated Services Router Version-
Cisco ≫ 1101-4p Integrated Services Router Version-
Cisco ≫ 1101 Integrated Services Router Version-
Cisco ≫ 1109-2p Integrated Services Router Version-
Cisco ≫ 1109-4p Integrated Services Router Version-
Cisco ≫ 1109 Integrated Services Router Version-
Cisco ≫ 1111x-8p Integrated Services Router Version-
Cisco ≫ 1111x Integrated Services Router Version-
Cisco ≫ 111x Integrated Services Router Version-
Cisco ≫ 1120 Integrated Services Router Version-
Cisco ≫ 1160 Integrated Services Router Version-
Cisco ≫ 4221 Integrated Services Router Version-
Cisco ≫ 4331 Integrated Services Router Version-
Cisco ≫ 4431 Integrated Services Router Version-
Cisco ≫ 4451 Integrated Services Router Version-
Cisco ≫ 4461 Integrated Services Router Version-
Cisco ≫ Asr 1000-x Version-
Cisco ≫ Asr 1001 Version-
Cisco ≫ Asr 1001-x Version-
Cisco ≫ Asr 1002 Version-
Cisco ≫ Asr 1002-x Version-
Cisco ≫ Asr 1004 Version-
Cisco ≫ Asr 1006 Version-
Cisco ≫ Asr 1013 Version-
Cisco ≫ Asr1001-hx Version-
Cisco ≫ Asr1001-hx-rf Version-
Cisco ≫ Asr1001-x-rf Version-
Cisco ≫ Asr1001-x-ws Version-
Cisco ≫ Asr1002-hx Version-
Cisco ≫ Asr1002-hx-rf Version-
Cisco ≫ Asr1002-hx-ws Version-
Cisco ≫ Asr1002-x-rf Version-
Cisco ≫ Asr1002-x-ws Version-
Cisco ≫ Catalyst 9800-40 Version-
Cisco ≫ Catalyst 9800-80 Version-
Cisco ≫ Catalyst 9800-cl Version-
Cisco ≫ Catalyst 9800-l Version-
Cisco ≫ Catalyst 9800-l-c Version-
Cisco ≫ Catalyst 9800-l-f Version-
Cisco ≫ Catalyst C9200-24p Version-
Cisco ≫ Catalyst C9200-24t Version-
Cisco ≫ Catalyst C9200-48p Version-
Cisco ≫ Catalyst C9200-48t Version-
Cisco ≫ Catalyst C9200l-24p-4g Version-
Cisco ≫ Catalyst C9200l-24p-4x Version-
Cisco ≫ Catalyst C9200l-24pxg-2y Version-
Cisco ≫ Catalyst C9200l-24pxg-4x Version-
Cisco ≫ Catalyst C9200l-24t-4g Version-
Cisco ≫ Catalyst C9200l-24t-4x Version-
Cisco ≫ Catalyst C9200l-48p-4g Version-
Cisco ≫ Catalyst C9200l-48p-4x Version-
Cisco ≫ Catalyst C9200l-48pxg-2y Version-
Cisco ≫ Catalyst C9200l-48pxg-4x Version-
Cisco ≫ Catalyst C9200l-48t-4g Version-
Cisco ≫ Catalyst C9200l-48t-4x Version-
Cisco ≫ Catalyst C9300-24p Version-
Cisco ≫ Catalyst C9300-24s Version-
Cisco ≫ Catalyst C9300-24t Version-
Cisco ≫ Catalyst C9300-24u Version-
Cisco ≫ Catalyst C9300-24ux Version-
Cisco ≫ Catalyst C9300-48p Version-
Cisco ≫ Catalyst C9300-48s Version-
Cisco ≫ Catalyst C9300-48t Version-
Cisco ≫ Catalyst C9300-48u Version-
Cisco ≫ Catalyst C9300-48un Version-
Cisco ≫ Catalyst C9300-48uxm Version-
Cisco ≫ Catalyst C9300l-24p-4g Version-
Cisco ≫ Catalyst C9300l-24p-4x Version-
Cisco ≫ Catalyst C9300l-24t-4g Version-
Cisco ≫ Catalyst C9300l-24t-4x Version-
Cisco ≫ Catalyst C9300l-48p-4g Version-
Cisco ≫ Catalyst C9300l-48p-4x Version-
Cisco ≫ Catalyst C9300l-48t-4g Version-
Cisco ≫ Catalyst C9300l-48t-4x Version-
Cisco ≫ Catalyst C9404r Version-
Cisco ≫ Catalyst C9407r Version-
Cisco ≫ Catalyst C9410r Version-
Cisco ≫ Catalyst C9500-12q Version-
Cisco ≫ Catalyst C9500-16x Version-
Cisco ≫ Catalyst C9500-24q Version-
Cisco ≫ Catalyst C9500-24y4c Version-
Cisco ≫ Catalyst C9500-32c Version-
Cisco ≫ Catalyst C9500-32qc Version-
Cisco ≫ Catalyst C9500-40x Version-
Cisco ≫ Catalyst C9500-48y4c Version-
Cisco ≫ Csr 1000v
Cisco ≫ Ws-c3650-12x48uq Version-
Cisco ≫ Ws-c3650-12x48ur Version-
Cisco ≫ Ws-c3650-12x48uz Version-
Cisco ≫ Ws-c3650-24pd Version-
Cisco ≫ Ws-c3650-24pdm Version-
Cisco ≫ Ws-c3650-24ps Version-
Cisco ≫ Ws-c3650-24td Version-
Cisco ≫ Ws-c3650-24ts Version-
Cisco ≫ Ws-c3650-48fd Version-
Cisco ≫ Ws-c3650-48fq Version-
Cisco ≫ Ws-c3650-48fqm Version-
Cisco ≫ Ws-c3650-48fs Version-
Cisco ≫ Ws-c3650-48pd Version-
Cisco ≫ Ws-c3650-48pq Version-
Cisco ≫ Ws-c3650-48ps Version-
Cisco ≫ Ws-c3650-48td Version-
Cisco ≫ Ws-c3650-48tq Version-
Cisco ≫ Ws-c3650-48ts Version-
Cisco ≫ Ws-c3650-8x24uq Version-
Cisco ≫ Ws-c3850 Version-
Cisco ≫ Ws-c3850-12s Version-
Cisco ≫ Ws-c3850-12x48u Version-
Cisco ≫ Ws-c3850-12xs Version-
Cisco ≫ Ws-c3850-24p Version-
Cisco ≫ Ws-c3850-24s Version-
Cisco ≫ Ws-c3850-24t Version-
Cisco ≫ Ws-c3850-24u Version-
Cisco ≫ Ws-c3850-24xs Version-
Cisco ≫ Ws-c3850-24xu Version-
Cisco ≫ Ws-c3850-48f Version-
Cisco ≫ Ws-c3850-48p Version-
Cisco ≫ Ws-c3850-48t Version-
Cisco ≫ Ws-c3850-48u Version-
Cisco ≫ Ws-c3850-48xs Version-
Cisco ≫ 1100-4gltegb Integrated Services Router Version-
Cisco ≫ 1100-4gltena Integrated Services Router Version-
Cisco ≫ 1100-4p Integrated Services Router Version-
Cisco ≫ 1100-6g Integrated Services Router Version-
Cisco ≫ 1100-8p Integrated Services Router Version-
Cisco ≫ 1100-lte Integrated Services Router Version-
Cisco ≫ 1100 Integrated Services Router Version-
Cisco ≫ 1101-4p Integrated Services Router Version-
Cisco ≫ 1101 Integrated Services Router Version-
Cisco ≫ 1109-2p Integrated Services Router Version-
Cisco ≫ 1109-4p Integrated Services Router Version-
Cisco ≫ 1109 Integrated Services Router Version-
Cisco ≫ 1111x-8p Integrated Services Router Version-
Cisco ≫ 1111x Integrated Services Router Version-
Cisco ≫ 111x Integrated Services Router Version-
Cisco ≫ 1120 Integrated Services Router Version-
Cisco ≫ 1160 Integrated Services Router Version-
Cisco ≫ 4221 Integrated Services Router Version-
Cisco ≫ 4331 Integrated Services Router Version-
Cisco ≫ 4431 Integrated Services Router Version-
Cisco ≫ 4451 Integrated Services Router Version-
Cisco ≫ 4461 Integrated Services Router Version-
Cisco ≫ Asr 1000-x Version-
Cisco ≫ Asr 1001 Version-
Cisco ≫ Asr 1001-x Version-
Cisco ≫ Asr 1002 Version-
Cisco ≫ Asr 1002-x Version-
Cisco ≫ Asr 1004 Version-
Cisco ≫ Asr 1006 Version-
Cisco ≫ Asr 1013 Version-
Cisco ≫ Asr1001-hx Version-
Cisco ≫ Asr1001-hx-rf Version-
Cisco ≫ Asr1001-x-rf Version-
Cisco ≫ Asr1001-x-ws Version-
Cisco ≫ Asr1002-hx Version-
Cisco ≫ Asr1002-hx-rf Version-
Cisco ≫ Asr1002-hx-ws Version-
Cisco ≫ Asr1002-x-rf Version-
Cisco ≫ Asr1002-x-ws Version-
Cisco ≫ Catalyst 9800-40 Version-
Cisco ≫ Catalyst 9800-80 Version-
Cisco ≫ Catalyst 9800-cl Version-
Cisco ≫ Catalyst 9800-l Version-
Cisco ≫ Catalyst 9800-l-c Version-
Cisco ≫ Catalyst 9800-l-f Version-
Cisco ≫ Catalyst C9200-24p Version-
Cisco ≫ Catalyst C9200-24t Version-
Cisco ≫ Catalyst C9200-48p Version-
Cisco ≫ Catalyst C9200-48t Version-
Cisco ≫ Catalyst C9200l-24p-4g Version-
Cisco ≫ Catalyst C9200l-24p-4x Version-
Cisco ≫ Catalyst C9200l-24pxg-2y Version-
Cisco ≫ Catalyst C9200l-24pxg-4x Version-
Cisco ≫ Catalyst C9200l-24t-4g Version-
Cisco ≫ Catalyst C9200l-24t-4x Version-
Cisco ≫ Catalyst C9200l-48p-4g Version-
Cisco ≫ Catalyst C9200l-48p-4x Version-
Cisco ≫ Catalyst C9200l-48pxg-2y Version-
Cisco ≫ Catalyst C9200l-48pxg-4x Version-
Cisco ≫ Catalyst C9200l-48t-4g Version-
Cisco ≫ Catalyst C9200l-48t-4x Version-
Cisco ≫ Catalyst C9300-24p Version-
Cisco ≫ Catalyst C9300-24s Version-
Cisco ≫ Catalyst C9300-24t Version-
Cisco ≫ Catalyst C9300-24u Version-
Cisco ≫ Catalyst C9300-24ux Version-
Cisco ≫ Catalyst C9300-48p Version-
Cisco ≫ Catalyst C9300-48s Version-
Cisco ≫ Catalyst C9300-48t Version-
Cisco ≫ Catalyst C9300-48u Version-
Cisco ≫ Catalyst C9300-48un Version-
Cisco ≫ Catalyst C9300-48uxm Version-
Cisco ≫ Catalyst C9300l-24p-4g Version-
Cisco ≫ Catalyst C9300l-24p-4x Version-
Cisco ≫ Catalyst C9300l-24t-4g Version-
Cisco ≫ Catalyst C9300l-24t-4x Version-
Cisco ≫ Catalyst C9300l-48p-4g Version-
Cisco ≫ Catalyst C9300l-48p-4x Version-
Cisco ≫ Catalyst C9300l-48t-4g Version-
Cisco ≫ Catalyst C9300l-48t-4x Version-
Cisco ≫ Catalyst C9404r Version-
Cisco ≫ Catalyst C9407r Version-
Cisco ≫ Catalyst C9410r Version-
Cisco ≫ Catalyst C9500-12q Version-
Cisco ≫ Catalyst C9500-16x Version-
Cisco ≫ Catalyst C9500-24q Version-
Cisco ≫ Catalyst C9500-24y4c Version-
Cisco ≫ Catalyst C9500-32c Version-
Cisco ≫ Catalyst C9500-32qc Version-
Cisco ≫ Catalyst C9500-40x Version-
Cisco ≫ Catalyst C9500-48y4c Version-
Cisco ≫ Csr 1000v
Cisco ≫ Ws-c3650-12x48uq Version-
Cisco ≫ Ws-c3650-12x48ur Version-
Cisco ≫ Ws-c3650-12x48uz Version-
Cisco ≫ Ws-c3650-24pd Version-
Cisco ≫ Ws-c3650-24pdm Version-
Cisco ≫ Ws-c3650-24ps Version-
Cisco ≫ Ws-c3650-24td Version-
Cisco ≫ Ws-c3650-24ts Version-
Cisco ≫ Ws-c3650-48fd Version-
Cisco ≫ Ws-c3650-48fq Version-
Cisco ≫ Ws-c3650-48fqm Version-
Cisco ≫ Ws-c3650-48fs Version-
Cisco ≫ Ws-c3650-48pd Version-
Cisco ≫ Ws-c3650-48pq Version-
Cisco ≫ Ws-c3650-48ps Version-
Cisco ≫ Ws-c3650-48td Version-
Cisco ≫ Ws-c3650-48tq Version-
Cisco ≫ Ws-c3650-48ts Version-
Cisco ≫ Ws-c3650-8x24uq Version-
Cisco ≫ Ws-c3850 Version-
Cisco ≫ Ws-c3850-12s Version-
Cisco ≫ Ws-c3850-12x48u Version-
Cisco ≫ Ws-c3850-12xs Version-
Cisco ≫ Ws-c3850-24p Version-
Cisco ≫ Ws-c3850-24s Version-
Cisco ≫ Ws-c3850-24t Version-
Cisco ≫ Ws-c3850-24u Version-
Cisco ≫ Ws-c3850-24xs Version-
Cisco ≫ Ws-c3850-24xu Version-
Cisco ≫ Ws-c3850-48f Version-
Cisco ≫ Ws-c3850-48p Version-
Cisco ≫ Ws-c3850-48t Version-
Cisco ≫ Ws-c3850-48u Version-
Cisco ≫ Ws-c3850-48xs Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.096 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:P/I:P/A:N
|
psirt@cisco.com | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.