First published: Wed Jun 03 2020(Updated: )
A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability is due to an improper check on the area of code that manages the verification of the digital signatures of system image files during the initial boot process. An attacker could exploit this vulnerability by loading unsigned software on an affected device. A successful exploit could allow the attacker to install and boot a malicious software image or execute unsigned binaries on the targeted device.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =3.2.0se | |
Cisco IOS XE Software | =3.2.0sg | |
Cisco IOS XE Software | =3.2.1se | |
Cisco IOS XE Software | =3.2.1sg | |
Cisco IOS XE Software | =3.2.2se | |
Cisco IOS XE Software | =3.2.2sg | |
Cisco IOS XE Software | =3.2.3se | |
Cisco IOS XE Software | =3.2.3sg | |
Cisco IOS XE Software | =3.2.4sg | |
Cisco IOS XE Software | =3.2.5sg | |
Cisco IOS XE Software | =3.2.6sg | |
Cisco IOS XE Software | =3.2.7sg | |
Cisco IOS XE Software | =3.2.8sg | |
Cisco IOS XE Software | =3.2.9sg | |
Cisco IOS XE Software | =3.2.10sg | |
Cisco IOS XE Software | =3.2.11sg | |
Cisco IOS XE Software | =3.3.0se | |
Cisco IOS XE Software | =3.3.0sg | |
Cisco IOS XE Software | =3.3.0sq | |
Cisco IOS XE Software | =3.3.0xo | |
Cisco IOS XE Software | =3.3.1se | |
Cisco IOS XE Software | =3.3.1sg | |
Cisco IOS XE Software | =3.3.1sq | |
Cisco IOS XE Software | =3.3.1xo | |
Cisco IOS XE Software | =3.3.2se | |
Cisco IOS XE Software | =3.3.2sg | |
Cisco IOS XE Software | =3.3.2xo | |
Cisco IOS XE Software | =3.3.3se | |
Cisco IOS XE Software | =3.3.4se | |
Cisco IOS XE Software | =3.3.5se | |
Cisco IOS XE Software | =3.4.0sg | |
Cisco IOS XE Software | =3.4.0sq | |
Cisco IOS XE Software | =3.4.1sg | |
Cisco IOS XE Software | =3.4.1sq | |
Cisco IOS XE Software | =3.4.2sg | |
Cisco IOS XE Software | =3.4.3sg | |
Cisco IOS XE Software | =3.4.4sg | |
Cisco IOS XE Software | =3.4.5sg | |
Cisco IOS XE Software | =3.4.6sg | |
Cisco IOS XE Software | =3.4.7sg | |
Cisco IOS XE Software | =3.4.8sg | |
Cisco IOS XE Software | =3.5.0e | |
Cisco IOS XE Software | =3.5.0sq | |
Cisco IOS XE Software | =3.5.1e | |
Cisco IOS XE Software | =3.5.1sq | |
Cisco IOS XE Software | =3.5.2e | |
Cisco IOS XE Software | =3.5.2sq | |
Cisco IOS XE Software | =3.5.3e | |
Cisco IOS XE Software | =3.5.3sq | |
Cisco IOS XE Software | =3.5.4sq | |
Cisco IOS XE Software | =3.5.5sq | |
Cisco IOS XE Software | =3.5.6sq | |
Cisco IOS XE Software | =3.5.7sq | |
Cisco IOS XE Software | =3.5.8sq | |
Cisco IOS XE Software | =3.6.0ae | |
Cisco IOS XE Software | =3.6.0be | |
Cisco IOS XE Software | =3.6.0e | |
Cisco IOS XE Software | =3.6.1e | |
Cisco IOS XE Software | =3.6.2ae | |
Cisco IOS XE Software | =3.6.3e | |
Cisco IOS XE Software | =3.6.4e | |
Cisco IOS XE Software | =3.6.5ae | |
Cisco IOS XE Software | =3.6.5be | |
Cisco IOS XE Software | =3.6.5e | |
Cisco IOS XE Software | =3.6.6e | |
Cisco IOS XE Software | =3.6.7ae | |
Cisco IOS XE Software | =3.6.7be | |
Cisco IOS XE Software | =3.6.7e | |
Cisco IOS XE Software | =3.6.8e | |
Cisco IOS XE Software | =3.6.9ae | |
Cisco IOS XE Software | =3.6.9e | |
Cisco IOS XE Software | =3.6.10e | |
Cisco IOS XE Software | =3.7.0bs | |
Cisco IOS XE Software | =3.7.0e | |
Cisco IOS XE Software | =3.7.0s | |
Cisco IOS XE Software | =3.7.1as | |
Cisco IOS XE Software | =3.7.1e | |
Cisco IOS XE Software | =3.7.1s | |
Cisco IOS XE Software | =3.7.2e | |
Cisco IOS XE Software | =3.7.2s | |
Cisco IOS XE Software | =3.7.2ts | |
Cisco IOS XE Software | =3.7.3e | |
Cisco IOS XE Software | =3.7.3s | |
Cisco IOS XE Software | =3.7.4as | |
Cisco IOS XE Software | =3.7.4e | |
Cisco IOS XE Software | =3.7.4s | |
Cisco IOS XE Software | =3.7.5e | |
Cisco IOS XE Software | =3.7.5s | |
Cisco IOS XE Software | =3.7.6s | |
Cisco IOS XE Software | =3.7.7s | |
Cisco IOS XE Software | =3.7.8s | |
Cisco IOS XE Software | =3.8.0e | |
Cisco IOS XE Software | =3.8.0s | |
Cisco IOS XE Software | =3.8.1e | |
Cisco IOS XE Software | =3.8.1s | |
Cisco IOS XE Software | =3.8.2e | |
Cisco IOS XE Software | =3.8.2s | |
Cisco IOS XE Software | =3.8.3e | |
Cisco IOS XE Software | =3.8.4e | |
Cisco IOS XE Software | =3.8.5ae | |
Cisco IOS XE Software | =3.8.5e | |
Cisco IOS XE Software | =3.8.6e | |
Cisco IOS XE Software | =3.8.7e | |
Cisco IOS XE Software | =3.8.8e | |
Cisco IOS XE Software | =3.8.9e | |
Cisco IOS XE Software | =3.9.0as | |
Cisco IOS XE Software | =3.9.0e | |
Cisco IOS XE Software | =3.9.0s | |
Cisco IOS XE Software | =3.9.1as | |
Cisco IOS XE Software | =3.9.1e | |
Cisco IOS XE Software | =3.9.1s | |
Cisco IOS XE Software | =3.9.2be | |
Cisco IOS XE Software | =3.9.2e | |
Cisco IOS XE Software | =3.9.2s | |
Cisco IOS XE Software | =3.10.0ce | |
Cisco IOS XE Software | =3.10.0e | |
Cisco IOS XE Software | =3.10.0s | |
Cisco IOS XE Software | =3.10.1ae | |
Cisco IOS XE Software | =3.10.1e | |
Cisco IOS XE Software | =3.10.1s | |
Cisco IOS XE Software | =3.10.1se | |
Cisco IOS XE Software | =3.10.2as | |
Cisco IOS XE Software | =3.10.2e | |
Cisco IOS XE Software | =3.10.2s | |
Cisco IOS XE Software | =3.10.2ts | |
Cisco IOS XE Software | =3.10.3e | |
Cisco IOS XE Software | =3.10.3s | |
Cisco IOS XE Software | =3.10.4s | |
Cisco IOS XE Software | =3.10.5s | |
Cisco IOS XE Software | =3.10.6s | |
Cisco IOS XE Software | =3.10.7s | |
Cisco IOS XE Software | =3.10.8as | |
Cisco IOS XE Software | =3.10.8s | |
Cisco IOS XE Software | =3.10.9s | |
Cisco IOS XE Software | =3.10.10s | |
Cisco IOS XE Software | =3.11.0e | |
Cisco IOS XE Software | =3.11.0s | |
Cisco IOS XE Software | =3.11.1e | |
Cisco IOS XE Software | =3.11.1s | |
Cisco IOS XE Software | =3.11.2s | |
Cisco IOS XE Software | =3.11.3e | |
Cisco IOS XE Software | =3.11.3s | |
Cisco IOS XE Software | =3.11.4s | |
Cisco IOS XE Software | =3.12.0as | |
Cisco IOS XE Software | =3.12.0s | |
Cisco IOS XE Software | =3.12.1s | |
Cisco IOS XE Software | =3.12.2s | |
Cisco IOS XE Software | =3.12.3s | |
Cisco IOS XE Software | =3.12.4s | |
Cisco IOS XE Software | =3.13.0as | |
Cisco IOS XE Software | =3.13.0s | |
Cisco IOS XE Software | =3.13.1s | |
Cisco IOS XE Software | =3.13.2as | |
Cisco IOS XE Software | =3.13.2s | |
Cisco IOS XE Software | =3.13.3s | |
Cisco IOS XE Software | =3.13.4s | |
Cisco IOS XE Software | =3.13.5as | |
Cisco IOS XE Software | =3.13.5s | |
Cisco IOS XE Software | =3.13.6as | |
Cisco IOS XE Software | =3.13.6bs | |
Cisco IOS XE Software | =3.13.6s | |
Cisco IOS XE Software | =3.13.7as | |
Cisco IOS XE Software | =3.13.7s | |
Cisco IOS XE Software | =3.13.8s | |
Cisco IOS XE Software | =3.13.9s | |
Cisco IOS XE Software | =3.13.10s | |
Cisco IOS XE Software | =3.14.0s | |
Cisco IOS XE Software | =3.14.1s | |
Cisco IOS XE Software | =3.14.2s | |
Cisco IOS XE Software | =3.14.3s | |
Cisco IOS XE Software | =3.14.4s | |
Cisco IOS XE Software | =3.15.0s | |
Cisco IOS XE Software | =3.15.1cs | |
Cisco IOS XE Software | =3.15.1s | |
Cisco IOS XE Software | =3.15.2s | |
Cisco IOS XE Software | =3.15.3s | |
Cisco IOS XE Software | =3.15.4s | |
Cisco IOS XE Software | =3.16.0as | |
Cisco IOS XE Software | =3.16.0bs | |
Cisco IOS XE Software | =3.16.0cs | |
Cisco IOS XE Software | =3.16.0s | |
Cisco IOS XE Software | =3.16.1as | |
Cisco IOS XE Software | =3.16.1s | |
Cisco IOS XE Software | =3.16.2as | |
Cisco IOS XE Software | =3.16.2bs | |
Cisco IOS XE Software | =3.16.2s | |
Cisco IOS XE Software | =3.16.3as | |
Cisco IOS XE Software | =3.16.3s | |
Cisco IOS XE Software | =3.16.4as | |
Cisco IOS XE Software | =3.16.4bs | |
Cisco IOS XE Software | =3.16.4cs | |
Cisco IOS XE Software | =3.16.4ds | |
Cisco IOS XE Software | =3.16.4es | |
Cisco IOS XE Software | =3.16.4gs | |
Cisco IOS XE Software | =3.16.4s | |
Cisco IOS XE Software | =3.16.5as | |
Cisco IOS XE Software | =3.16.5bs | |
Cisco IOS XE Software | =3.16.5s | |
Cisco IOS XE Software | =3.16.6bs | |
Cisco IOS XE Software | =3.16.6s | |
Cisco IOS XE Software | =3.16.7as | |
Cisco IOS XE Software | =3.16.7bs | |
Cisco IOS XE Software | =3.16.7s | |
Cisco IOS XE Software | =3.16.8s | |
Cisco IOS XE Software | =3.16.9s | |
Cisco IOS XE Software | =3.16.10s | |
Cisco IOS XE Software | =3.17.0s | |
Cisco IOS XE Software | =3.17.1as | |
Cisco IOS XE Software | =3.17.1s | |
Cisco IOS XE Software | =3.17.2s | |
Cisco IOS XE Software | =3.17.3s | |
Cisco IOS XE Software | =3.17.4s | |
Cisco IOS XE Software | =3.18.0as | |
Cisco IOS XE Software | =3.18.0s | |
Cisco IOS XE Software | =3.18.0sp | |
Cisco IOS XE Software | =3.18.1asp | |
Cisco IOS XE Software | =3.18.1bsp | |
Cisco IOS XE Software | =3.18.1csp | |
Cisco IOS XE Software | =3.18.1gsp | |
Cisco IOS XE Software | =3.18.1hsp | |
Cisco IOS XE Software | =3.18.1isp | |
Cisco IOS XE Software | =3.18.1s | |
Cisco IOS XE Software | =3.18.1sp | |
Cisco IOS XE Software | =3.18.2asp | |
Cisco IOS XE Software | =3.18.2s | |
Cisco IOS XE Software | =3.18.2sp | |
Cisco IOS XE Software | =3.18.3asp | |
Cisco IOS XE Software | =3.18.3bsp | |
Cisco IOS XE Software | =3.18.3s | |
Cisco IOS XE Software | =3.18.3sp | |
Cisco IOS XE Software | =3.18.4s | |
Cisco IOS XE Software | =3.18.4sp | |
Cisco IOS XE Software | =3.18.5sp | |
Cisco IOS XE Software | =3.18.6sp | |
Cisco IOS XE Software | =3.18.7sp | |
Cisco IOS XE Software | =3.18.8sp | |
Cisco IOS XE Software | =16.1.1 | |
Cisco IOS XE Software | =16.1.2 | |
Cisco IOS XE Software | =16.1.3 | |
Cisco IOS XE Software | =16.2.1 | |
Cisco IOS XE Software | =16.2.2 | |
Cisco IOS XE Software | =16.3.1 | |
Cisco IOS XE Software | =16.3.1a | |
Cisco IOS XE Software | =16.3.2 | |
Cisco IOS XE Software | =16.3.3 | |
Cisco IOS XE Software | =16.3.4 | |
Cisco IOS XE Software | =16.3.5 | |
Cisco IOS XE Software | =16.3.5b | |
Cisco IOS XE Software | =16.3.6 | |
Cisco IOS XE Software | =16.3.7 | |
Cisco IOS XE Software | =16.3.8 | |
Cisco IOS XE Software | =16.4.1 | |
Cisco IOS XE Software | =16.4.2 | |
Cisco IOS XE Software | =16.4.3 | |
Cisco IOS XE Software | =16.5.1 | |
Cisco IOS XE Software | =16.5.1a | |
Cisco IOS XE Software | =16.5.1b | |
Cisco IOS XE Software | =16.5.2 | |
Cisco IOS XE Software | =16.5.3 | |
Cisco IOS XE Software | =16.6.1 | |
Cisco IOS XE Software | =16.6.2 | |
Cisco IOS XE Software | =16.6.3 | |
Cisco IOS XE Software | =16.6.4 | |
Cisco IOS XE Software | =16.6.4a | |
Cisco IOS XE Software | =16.6.4s | |
Cisco IOS XE Software | =16.6.5 | |
Cisco IOS XE Software | =16.6.5a | |
Cisco IOS XE Software | =16.6.5b | |
Cisco IOS XE Software | =16.6.6 | |
Cisco IOS XE Software | =16.6.7 | |
Cisco IOS XE Software | =16.6.7a | |
Cisco IOS XE Software | =16.7.1 | |
Cisco IOS XE Software | =16.7.1a | |
Cisco IOS XE Software | =16.7.1b | |
Cisco IOS XE Software | =16.7.2 | |
Cisco IOS XE Software | =16.7.3 | |
Cisco IOS XE Software | =16.7.4 | |
Cisco IOS XE Software | =16.8.1 | |
Cisco IOS XE Software | =16.8.1a | |
Cisco IOS XE Software | =16.8.1b | |
Cisco IOS XE Software | =16.8.1c | |
Cisco IOS XE Software | =16.8.1d | |
Cisco IOS XE Software | =16.8.1e | |
Cisco IOS XE Software | =16.8.1s | |
Cisco IOS XE Software | =16.8.2 | |
Cisco IOS XE Software | =16.8.3 | |
Cisco IOS XE Software | =16.9.1 | |
Cisco IOS XE Software | =16.9.1a | |
Cisco IOS XE Software | =16.9.1b | |
Cisco IOS XE Software | =16.9.1c | |
Cisco IOS XE Software | =16.9.1d | |
Cisco IOS XE Software | =16.9.1s | |
Cisco IOS XE Software | =16.9.2 | |
Cisco IOS XE Software | =16.9.2a | |
Cisco IOS XE Software | =16.9.2s | |
Cisco IOS XE Software | =16.9.3 | |
Cisco IOS XE Software | =16.9.3h | |
Cisco IOS XE Software | =16.9.3s | |
Cisco IOS XE Software | =16.9.4 | |
Cisco IOS XE Software | =16.9.4c | |
Cisco IOS XE Software | =16.10.1 | |
Cisco IOS XE Software | =16.10.1a | |
Cisco IOS XE Software | =16.10.1b | |
Cisco IOS XE Software | =16.10.1c | |
Cisco IOS XE Software | =16.10.1d | |
Cisco IOS XE Software | =16.10.1e | |
Cisco IOS XE Software | =16.10.1f | |
Cisco IOS XE Software | =16.10.1g | |
Cisco IOS XE Software | =16.10.1s | |
Cisco IOS XE Software | =16.10.2 | |
Cisco IOS XE Software | =16.11.1 | |
Cisco IOS XE Software | =16.11.1a | |
Cisco IOS XE Software | =16.11.1b | |
Cisco IOS XE Software | =16.12.1y |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3209 is rated as high severity due to its potential to let an attacker install malicious software on affected devices.
To mitigate CVE-2020-3209, users should upgrade to the appropriate Cisco IOS XE software version that addresses this vulnerability.
CVE-2020-3209 affects Cisco IOS XE versions 3.2.0se, 3.2.0sg, 3.2.1se, 3.2.1sg, and up to 3.17.4s.
If exploited, CVE-2020-3209 could allow an unauthorized user to execute unsigned binaries and potentially take control of the affected device.
Currently, Cisco does not recommend any specific workarounds for CVE-2020-3209 other than applying the relevant software updates.