CVE-2020-3198: Cisco IOS Software for Cisco Industrial Routers Arbitrary Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute arbitrary code on an affected system or cause an affected system to crash and reload. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3198?
CVE-2020-3198 is rated as high severity due to its potential for remote code execution.
Who is affected by CVE-2020-3198?
CVE-2020-3198 affects multiple versions of Cisco IOS Software on specific Cisco 809 and 829 Industrial ISR and CGR1000 routers.
How do I fix CVE-2020-3198?
To fix CVE-2020-3198, apply the relevant software updates provided by Cisco for affected IOS versions.
What type of vulnerability is CVE-2020-3198?
CVE-2020-3198 is a remote code execution vulnerability that can be exploited by unauthenticated attackers.
Can CVE-2020-3198 be exploited locally?
Yes, CVE-2020-3198 can also be exploited by authenticated local attackers.