CVE-2020-3474: Cisco IOS XE Software Web Management Framework Vulnerabilities
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, resulting in a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3474?
CVE-2020-3474 is rated as having a high severity, as it allows unauthorized read access to sensitive data.
How do I fix CVE-2020-3474?
To fix CVE-2020-3474, you should update the affected Cisco IOS XE Software to a version that includes the security patches.
What types of attacks can CVE-2020-3474 enable?
CVE-2020-3474 can enable authenticated attackers to gain unauthorized read access to sensitive data or cause the web management software to crash.
Which Cisco devices are affected by CVE-2020-3474?
CVE-2020-3474 affects multiple Cisco IOS XE software versions across various routing and switching devices.
What is the impact of CVE-2020-3474 on affected systems?
The impact of CVE-2020-3474 includes unauthorized access to sensitive data and the possibility of denial of service if the web management software malfunctions.