CVE-2020-3214: Cisco IOS XE Software Privilege Escalation Vulnerability
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileges. The vulnerability is due to insufficient validation of user-supplied content. This vulnerability could allow an attacker to load malicious software onto an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3214?
The severity of CVE-2020-3214 is rated as high due to its potential for unauthorized privilege escalation.
How do I fix CVE-2020-3214?
To fix CVE-2020-3214, you need to update the affected Cisco IOS XE Software to the latest secure version as specified in the advisory.
Who is affected by CVE-2020-3214?
CVE-2020-3214 affects users of Cisco IOS XE Software versions 16.11.1, 16.11.1a, 16.11.1b, 16.11.1c, 16.11.1s, 16.11.2, 16.12.1, 16.12.1a, 16.12.1c, 16.12.1s, 16.12.1t, 16.12.1w, and 16.12.1x.
What types of attacks can CVE-2020-3214 enable?
CVE-2020-3214 can enable local authenticated attackers to escalate privileges to root-level access.