CVE-2020-3218: Cisco IOS XE Software Web UI Remote Code Execution Vulnerability
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code with root privileges on the underlying Linux shell. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by first creating a malicious file on the affected device itself and then uploading a second malicious file to the device. A successful exploit could allow the attacker to execute arbitrary code with root privileges or bypass licensing requirements on the device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3218?
CVE-2020-3218 has been assigned a CVSS severity score of 9.8, indicating it is a critical vulnerability.
How do I fix CVE-2020-3218?
To fix CVE-2020-3218, upgrade to a patched version of Cisco IOS XE Software that addresses this vulnerability.
Who is affected by CVE-2020-3218?
CVE-2020-3218 affects users of Cisco IOS XE Software running specific vulnerable versions.
What does CVE-2020-3218 allow an attacker to do?
CVE-2020-3218 allows an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux shell.
Is authentication required to exploit CVE-2020-3218?
Yes, exploitation of CVE-2020-3218 requires administrative privileges for authentication.