CVE-2020-3425: Cisco IOS XE Software Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3425?
CVE-2020-3425 has a high severity rating, indicating a significant vulnerability in Cisco IOS XE Software.
How do I fix CVE-2020-3425?
To fix CVE-2020-3425, apply the latest security updates or patches provided by Cisco for affected IOS XE versions.
What versions of Cisco IOS XE are affected by CVE-2020-3425?
CVE-2020-3425 affects multiple versions of Cisco IOS XE, including versions 16.1.1 through 17.2.1.
Can CVE-2020-3425 lead to unauthorized access?
Yes, CVE-2020-3425 can allow an authenticated, remote attacker to elevate their privileges to that of an Administrator on the device.
Is there a workaround for CVE-2020-3425 if immediate patching is not possible?
While patching is the preferred solution, temporarily restricting access to the web management interface can mitigate risks associated with CVE-2020-3425.