CVE-2020-3475: Cisco IOS XE Software Web Management Framework Vulnerabilities
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, resulting in a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3475?
CVE-2020-3475 is rated as a high-severity vulnerability.
How do I fix CVE-2020-3475?
To fix CVE-2020-3475, you should upgrade your Cisco IOS XE software to the latest version.
What type of access does CVE-2020-3475 allow to an attacker?
CVE-2020-3475 allows an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data.
Can CVE-2020-3475 cause denial of service?
Yes, CVE-2020-3475 can cause the web management software to hang or crash, resulting in a denial of service.
Which Cisco products are affected by CVE-2020-3475?
CVE-2020-3475 affects multiple models of Cisco IOS XE Software, including the Cisco Catalyst and ASR series.