CVE-2020-3222
Cisco IOS XE Software Web UI Unauthenticated Proxy Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass access control restrictions on an affected device. The vulnerability is due to the presence of a proxy service at a specific endpoint of the web UI. An attacker could exploit this vulnerability by connecting to the proxy service. An exploit could allow the attacker to bypass access restrictions on the network by proxying their access request through the management network of the affected device. As the proxy is reached over the management virtual routing and forwarding (VRF), this could reduce the effectiveness of the bypass.
Una vulnerabilidad en la interfaz de usuario basada en web (UI web) de Cisco IOS XE Software, podría permitir a un atacante adyacente no autenticado omitir las restricciones de control de acceso sobre un dispositivo afectado. La vulnerabilidad es debido a la presencia de un servicio proxy en un endpoint específico de la Interfaz de Usuario web. Un atacante podría explotar esta vulnerabilidad conectándose al servicio de proxy. Una explotación podría permitir al atacante omitir las restricciones de acceso a la red mediante el procesamiento proxy de su petición de acceso por medio de la red de administración del dispositivo afectado. A medida que se alcanza el proxy por medio del enrutamiento y reenvío virtual de gestión (VRF), esto podría reducir la eficacia de la omisión.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-12-12 CVE Reserved
- 2020-06-03 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-17: DEPRECATED: Code
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-unauthprxy-KXXsbWh | 2021-09-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1 Search vendor "Cisco" for product "Ios Xe" and version "16.10.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1a Search vendor "Cisco" for product "Ios Xe" and version "16.10.1a" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1b Search vendor "Cisco" for product "Ios Xe" and version "16.10.1b" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1c Search vendor "Cisco" for product "Ios Xe" and version "16.10.1c" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1d Search vendor "Cisco" for product "Ios Xe" and version "16.10.1d" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1e Search vendor "Cisco" for product "Ios Xe" and version "16.10.1e" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1f Search vendor "Cisco" for product "Ios Xe" and version "16.10.1f" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1g Search vendor "Cisco" for product "Ios Xe" and version "16.10.1g" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.1s Search vendor "Cisco" for product "Ios Xe" and version "16.10.1s" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.10.2 Search vendor "Cisco" for product "Ios Xe" and version "16.10.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1a Search vendor "Cisco" for product "Ios Xe" and version "16.11.1a" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1b Search vendor "Cisco" for product "Ios Xe" and version "16.11.1b" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1c Search vendor "Cisco" for product "Ios Xe" and version "16.11.1c" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1s Search vendor "Cisco" for product "Ios Xe" and version "16.11.1s" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.12.1 Search vendor "Cisco" for product "Ios Xe" and version "16.12.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.12.1a Search vendor "Cisco" for product "Ios Xe" and version "16.12.1a" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.12.1c Search vendor "Cisco" for product "Ios Xe" and version "16.12.1c" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.12.1s Search vendor "Cisco" for product "Ios Xe" and version "16.12.1s" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.12.1t Search vendor "Cisco" for product "Ios Xe" and version "16.12.1t" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.12.1w Search vendor "Cisco" for product "Ios Xe" and version "16.12.1w" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.12.1y Search vendor "Cisco" for product "Ios Xe" and version "16.12.1y" | - |
Affected
|