// For flags

CVE-2020-3417

Cisco IOS XE Software Arbitrary Code Execution Vulnerability

Severity Score

6.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of trust. This vulnerability is due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set. An attacker could exploit this vulnerability by installing code to a specific directory in the underlying operating system (OS) and setting a specific ROMMON variable. A successful exploit could allow the attacker to execute persistent code on the underlying OS. To exploit this vulnerability, the attacker would need access to the root shell on the device or have physical access to the device.

Una vulnerabilidad en Cisco IOS XE Software podría permitir a un atacante local autenticado ejecutar código persistente en el momento del arranque y romper la cadena de confianza. Esta vulnerabilidad es debido a comprobaciones incorrectas para scripts de arranque cuando son configuradas variables específicas del monitor ROM (ROMMON). Un atacante podría explotar esta vulnerabilidad mediante la instalación del código en un directorio específico del sistema operativo (SO) subyacente y configurando una variable ROMMON específica. Una explotación con éxito podría permitir al atacante ejecutar código persistente en el sistema operativo subyacente. Para explotar esta vulnerabilidad, el atacante necesitaría acceder al shell root del dispositivo o contar con acceso físico al dispositivo.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-12-12 CVE Reserved
  • 2020-09-24 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.0sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.0sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.1asp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.1asp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.1bsp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.1bsp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.1csp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.1csp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.1gsp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.1gsp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.1hsp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.1hsp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.1isp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.1isp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.1sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.1sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.2asp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.2asp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.2sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.2sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.3asp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.3asp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.3bsp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.3bsp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.3sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.3sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.4sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.4sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.5sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.5sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.6sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.6sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.7sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.7sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.8asp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.8asp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.18.8sp
Search vendor "Cisco" for product "Ios Xe" and version "3.18.8sp"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.1
Search vendor "Cisco" for product "Ios Xe" and version "16.6.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.2
Search vendor "Cisco" for product "Ios Xe" and version "16.6.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.3
Search vendor "Cisco" for product "Ios Xe" and version "16.6.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.4
Search vendor "Cisco" for product "Ios Xe" and version "16.6.4"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.4a
Search vendor "Cisco" for product "Ios Xe" and version "16.6.4a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.4s
Search vendor "Cisco" for product "Ios Xe" and version "16.6.4s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5a
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5b
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.6
Search vendor "Cisco" for product "Ios Xe" and version "16.6.6"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.7
Search vendor "Cisco" for product "Ios Xe" and version "16.6.7"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.7a
Search vendor "Cisco" for product "Ios Xe" and version "16.6.7a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "16.7.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.7.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.7.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.2
Search vendor "Cisco" for product "Ios Xe" and version "16.7.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.3
Search vendor "Cisco" for product "Ios Xe" and version "16.7.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.4
Search vendor "Cisco" for product "Ios Xe" and version "16.7.4"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1c
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1c"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1d
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1d"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1e
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1e"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1s
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.2
Search vendor "Cisco" for product "Ios Xe" and version "16.8.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.3
Search vendor "Cisco" for product "Ios Xe" and version "16.8.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1c
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1c"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1d
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1d"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1s
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.2
Search vendor "Cisco" for product "Ios Xe" and version "16.9.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.2a
Search vendor "Cisco" for product "Ios Xe" and version "16.9.2a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.2s
Search vendor "Cisco" for product "Ios Xe" and version "16.9.2s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.3
Search vendor "Cisco" for product "Ios Xe" and version "16.9.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.3a
Search vendor "Cisco" for product "Ios Xe" and version "16.9.3a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.3h
Search vendor "Cisco" for product "Ios Xe" and version "16.9.3h"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.3s
Search vendor "Cisco" for product "Ios Xe" and version "16.9.3s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.4
Search vendor "Cisco" for product "Ios Xe" and version "16.9.4"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.4c
Search vendor "Cisco" for product "Ios Xe" and version "16.9.4c"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.5
Search vendor "Cisco" for product "Ios Xe" and version "16.9.5"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.5f
Search vendor "Cisco" for product "Ios Xe" and version "16.9.5f"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1c
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1c"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1d
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1d"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1e
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1e"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1f
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1f"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1g
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1g"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.1s
Search vendor "Cisco" for product "Ios Xe" and version "16.10.1s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.2
Search vendor "Cisco" for product "Ios Xe" and version "16.10.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.10.3
Search vendor "Cisco" for product "Ios Xe" and version "16.10.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.11.1
Search vendor "Cisco" for product "Ios Xe" and version "16.11.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.11.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.11.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.11.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.11.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.11.1c
Search vendor "Cisco" for product "Ios Xe" and version "16.11.1c"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.11.1s
Search vendor "Cisco" for product "Ios Xe" and version "16.11.1s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.11.2
Search vendor "Cisco" for product "Ios Xe" and version "16.11.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.1
Search vendor "Cisco" for product "Ios Xe" and version "16.12.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.12.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.1c
Search vendor "Cisco" for product "Ios Xe" and version "16.12.1c"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.1s
Search vendor "Cisco" for product "Ios Xe" and version "16.12.1s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.1t
Search vendor "Cisco" for product "Ios Xe" and version "16.12.1t"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.1w
Search vendor "Cisco" for product "Ios Xe" and version "16.12.1w"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.1x
Search vendor "Cisco" for product "Ios Xe" and version "16.12.1x"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.1y
Search vendor "Cisco" for product "Ios Xe" and version "16.12.1y"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.2
Search vendor "Cisco" for product "Ios Xe" and version "16.12.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.2a
Search vendor "Cisco" for product "Ios Xe" and version "16.12.2a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.2s
Search vendor "Cisco" for product "Ios Xe" and version "16.12.2s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.2t
Search vendor "Cisco" for product "Ios Xe" and version "16.12.2t"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.3
Search vendor "Cisco" for product "Ios Xe" and version "16.12.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.12.3a
Search vendor "Cisco" for product "Ios Xe" and version "16.12.3a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
17.1.1
Search vendor "Cisco" for product "Ios Xe" and version "17.1.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
17.1.1a
Search vendor "Cisco" for product "Ios Xe" and version "17.1.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
17.1.1s
Search vendor "Cisco" for product "Ios Xe" and version "17.1.1s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
17.1.1t
Search vendor "Cisco" for product "Ios Xe" and version "17.1.1t"
-
Affected