CVE-2020-3229: Cisco IOS XE Software Web UI Privilege Escalation Vulnerability
A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerability is due to incorrect handling of RBAC for the administration GUI. An attacker could exploit this vulnerability by sending a modified HTTP request to the affected device. An exploit could allow the attacker as a Read-Only user to execute CLI commands or configuration changes as if they were an Admin user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3229?
CVE-2020-3229 is rated as high severity due to its impact on Role Based Access Control (RBAC).
How do I fix CVE-2020-3229?
To fix CVE-2020-3229, apply the latest software updates released by Cisco for affected versions of IOS XE.
What versions of Cisco IOS XE are affected by CVE-2020-3229?
CVE-2020-3229 affects multiple Cisco IOS XE versions including 16.2.2 and 16.3.x up to 16.12.1y.
Can a remote attacker exploit CVE-2020-3229?
Yes, a remote, authenticated attacker can exploit CVE-2020-3229 to execute commands or make configuration changes as an Admin user.
Is authentication required to exploit CVE-2020-3229?
Yes, the attacker must have authenticated read-only access to exploit CVE-2020-3229.