// For flags

CVE-2020-3545

Cisco FXOS Software Buffer Overflow Vulnerability

Severity Score

6.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

A vulnerability in Cisco FXOS Software could allow an authenticated, local attacker with administrative credentials to cause a buffer overflow condition. The vulnerability is due to incorrect bounds checking of values that are parsed from a specific file. An attacker could exploit this vulnerability by supplying a crafted file that, when it is processed, may cause a stack-based buffer overflow. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system with root privileges. An attacker would need to have valid administrative credentials to exploit this vulnerability.

Una vulnerabilidad en Cisco FXOS Software podría permitir a un atacante local autenticado con credenciales administrativas causar una condición de desbordamiento del búfer. La vulnerabilidad es debido a una comprobación incorrecta de límites de los valores que son analizados desde un archivo específico. Un atacante podría explotar esta vulnerabilidad al suministrar un archivo diseñado que, cuando es procesado, puede causar un desbordamiento del búfer en la región stack de la memoria. Una explotación con éxito podría permitir al atacante ejecutar código arbitrario en el sistema operativo subyacente con privilegios root. Un atacante necesitaría tener credenciales administrativas válidas para explotar esta vulnerabilidad

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2019-12-12 CVE Reserved
  • 2020-09-04 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-11-13 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4110
Search vendor "Cisco" for product "Firepower 4110"
--
Safe
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4112
Search vendor "Cisco" for product "Firepower 4112"
--
Safe
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4115
Search vendor "Cisco" for product "Firepower 4115"
--
Safe
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4120
Search vendor "Cisco" for product "Firepower 4120"
--
Safe
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4125
Search vendor "Cisco" for product "Firepower 4125"
--
Safe
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4140
Search vendor "Cisco" for product "Firepower 4140"
--
Safe
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4145
Search vendor "Cisco" for product "Firepower 4145"
--
Safe
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4150
Search vendor "Cisco" for product "Firepower 4150"
--
Safe
Cisco
Search vendor "Cisco"
Firepower Extensible Operating System
Search vendor "Cisco" for product "Firepower Extensible Operating System"
<= 2.3.1.58
Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.3.1.58"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 9300
Search vendor "Cisco" for product "Firepower 9300"
--
Safe