First published: Wed Jun 03 2020(Updated: )
Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-iot-gos-vuln-s9qS8kYL This advisory is part of the June 3, 2020, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 23 Cisco Security Advisories that describe 25 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: June 2020 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication.
Credit: X.B. the Cisco Advanced Security Initiatives GroupE.I. Cisco PSIRT
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Cisco IOS | ||
Cisco 809 Industrial Integrated Services Router Firmware | ||
Cisco 829 Industrial Integrated Services Router Firmware | ||
Cisco 1000 Series Connected Grid Routers | = |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-ios-iot-gos-vuln-s9qS8kYL is rated as high, indicating a significant risk to affected devices.
To fix cisco-sa-ios-iot-gos-vuln-s9qS8kYL, it is recommended to update to the latest Cisco IOS Software version that addresses these vulnerabilities.
cisco-sa-ios-iot-gos-vuln-s9qS8kYL affects Cisco 809 and 829 Industrial Integrated Services Routers as well as Cisco 1000 Series Connected Grid Routers.
cisco-sa-ios-iot-gos-vuln-s9qS8kYL could be exploited to cause a denial of service attack, impacting the availability of the affected devices.
There are currently no recommended workarounds for cisco-sa-ios-iot-gos-vuln-s9qS8kYL; updating the software is the best approach.