CVE-2020-3201

MEDIUMCVSS 6/10EPSS 0.30%

Last modified

CVE-2020-3201 is a medium-severity vulnerability rated 6/10 on the CVSS scale. A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. EPSS estimates a 0.30% chance of exploitation in the next 30 days.

Description

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by executing crafted Tcl arguments on an affected device. An exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Metrics

CVSS 3.1
6/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

EPSS Probability
0.30%

21.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIos12.2\(18\)ixa
CiscoIos12.2\(18\)ixb
CiscoIos12.2\(18\)ixb1
CiscoIos12.2\(18\)ixb2
CiscoIos12.2\(18\)ixc
CiscoIos12.2\(18\)ixd
CiscoIos12.2\(18\)ixd1
CiscoIos12.2\(18\)ixe
CiscoIos12.2\(18\)ixf
CiscoIos12.2\(18\)ixf1
CiscoIos12.2\(18\)ixg
CiscoIos12.2\(18\)ixh
CiscoIos12.2\(18\)ixh1
CiscoIos12.2\(18\)sxe
CiscoIos12.2\(18\)sxe1
CiscoIos12.2\(18\)sxe2
CiscoIos12.2\(18\)sxe3
CiscoIos12.2\(18\)sxe4
CiscoIos12.2\(18\)sxe5
CiscoIos12.2\(18\)sxe6
CiscoIos12.2\(18\)sxe6a
CiscoIos12.2\(18\)sxe6b
CiscoIos12.2\(18\)sxf
CiscoIos12.2\(18\)sxf1
CiscoIos12.2\(18\)sxf2
CiscoIos12.2\(18\)sxf3
CiscoIos12.2\(18\)sxf4
CiscoIos12.2\(18\)sxf5
CiscoIos12.2\(18\)sxf6
CiscoIos12.2\(18\)sxf7
CiscoIos12.2\(18\)sxf8
CiscoIos12.2\(18\)sxf9
CiscoIos12.2\(18\)sxf10
CiscoIos12.2\(18\)sxf10a
CiscoIos12.2\(18\)sxf11
CiscoIos12.2\(18\)sxf12
CiscoIos12.2\(18\)sxf12a
CiscoIos12.2\(18\)sxf13
CiscoIos12.2\(18\)sxf13a
CiscoIos12.2\(18\)sxf13b
CiscoIos12.2\(18\)sxf14
CiscoIos12.2\(18\)sxf15
CiscoIos12.2\(18\)sxf15a
CiscoIos12.2\(18\)sxf16
CiscoIos12.2\(18\)sxf17
CiscoIos12.2\(18\)sxf17a
CiscoIos12.2\(18\)sxf17b
CiscoIos12.2\(18\)zu
CiscoIos12.2\(18\)zu1
CiscoIos12.2\(18\)zu2

Showing 50 of 1917 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-3201?
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by executing crafted Tcl arguments on an affected device. An exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
How severe is CVE-2020-3201?
CVE-2020-3201 has a CVSS score of 6/10 (MEDIUM severity). The EPSS model estimates a 0.30% probability of exploitation in the next 30 days.
How do I fix CVE-2020-3201?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-3201?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST