CVE-2020-3417: Cisco IOS XE Software Arbitrary Code Execution Vulnerability
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of trust. This vulnerability is due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set. An attacker could exploit this vulnerability by installing code to a specific directory in the underlying operating system (OS) and setting a specific ROMMON variable. A successful exploit could allow the attacker to execute persistent code on the underlying OS. To exploit this vulnerability, the attacker would need access to the root shell on the device or have physical access to the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3417?
CVE-2020-3417 is rated as high severity due to its ability to allow an authenticated attacker to execute persistent code.
How do I fix CVE-2020-3417?
To fix CVE-2020-3417, upgrade Cisco IOS XE Software to a version that addresses this vulnerability.
Who is affected by CVE-2020-3417?
CVE-2020-3417 affects devices running specific versions of Cisco IOS XE Software as listed in the advisory.
Can CVE-2020-3417 be exploited remotely?
No, CVE-2020-3417 requires local authenticated access to exploit.
What are the consequences of CVE-2020-3417?
Exploitation of CVE-2020-3417 can lead to the execution of arbitrary code at boot time, breaking the chain of trust.