CVE-2020-3219: Cisco IOS XE Software Web UI Command Injection Vulnerability
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of user-supplied input to the web UI. An attacker could exploit this vulnerability by submitting crafted input to the web UI. A successful exploit could allow an attacker to execute arbitrary commands with administrative privileges on an affected device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3219?
CVE-2020-3219 has a critical severity rating that allows authenticated attackers to execute arbitrary commands on affected Cisco IOS XE devices.
How do I fix CVE-2020-3219?
To fix CVE-2020-3219, apply the latest patches released by Cisco for the affected IOS XE versions.
What versions of Cisco IOS XE are affected by CVE-2020-3219?
CVE-2020-3219 affects Cisco IOS XE versions 16.1.1 through 16.12.1y.
Are there any workarounds for CVE-2020-3219?
No specific workarounds have been provided for CVE-2020-3219; updating to fixed versions is recommended.
Who is impacted by CVE-2020-3219?
Organizations using the affected Cisco IOS XE versions are at risk of exploitation through CVE-2020-3219.