CVE-2020-3204

MEDIUMCVSS 6.7/10EPSS 0.38%

Last modified

CVE-2020-3204 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. EPSS estimates a 0.38% chance of exploitation in the next 30 days.

Description

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by loading malicious Tcl code on an affected device. A successful exploit could allow the attacker to cause memory corruption or execute the code with root privileges on the underlying OS of the affected device.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.38%

29.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIos12.2\(6\)i1
CiscoIos12.2\(33\)sre
CiscoIos12.2\(33\)sre0a
CiscoIos12.2\(33\)sre1
CiscoIos12.2\(33\)sre2
CiscoIos12.2\(33\)sre3
CiscoIos12.2\(33\)sre4
CiscoIos12.2\(33\)sre5
CiscoIos12.2\(33\)sre6
CiscoIos12.2\(33\)sre7
CiscoIos12.2\(33\)sre7a
CiscoIos12.2\(33\)sre8
CiscoIos12.2\(33\)sre9
CiscoIos12.2\(33\)sre9a
CiscoIos12.2\(33\)sre10
CiscoIos12.2\(33\)sre11
CiscoIos12.2\(33\)sre12
CiscoIos12.2\(33\)sre13
CiscoIos12.2\(33\)sre14
CiscoIos12.2\(33\)sre15
CiscoIos12.2\(33\)sre15a
CiscoIos12.2\(33\)sxi
CiscoIos12.2\(33\)sxi1
CiscoIos12.2\(33\)sxi2
CiscoIos12.2\(33\)sxi2a
CiscoIos12.2\(33\)sxi3
CiscoIos12.2\(33\)sxi3a
CiscoIos12.2\(33\)sxi3z
CiscoIos12.2\(33\)sxi4
CiscoIos12.2\(33\)sxi4a
CiscoIos12.2\(33\)sxi5
CiscoIos12.2\(33\)sxi5a
CiscoIos12.2\(33\)sxi6
CiscoIos12.2\(33\)sxi7
CiscoIos12.2\(33\)sxi8
CiscoIos12.2\(33\)sxi8a
CiscoIos12.2\(33\)sxi9
CiscoIos12.2\(33\)sxi9a
CiscoIos12.2\(33\)sxi10
CiscoIos12.2\(33\)sxi11
CiscoIos12.2\(33\)sxi12
CiscoIos12.2\(33\)sxi13
CiscoIos12.2\(33\)sxi14
CiscoIos12.2\(33\)sxj
CiscoIos12.2\(33\)sxj1
CiscoIos12.2\(33\)sxj2
CiscoIos12.2\(33\)sxj3
CiscoIos12.2\(33\)sxj4
CiscoIos12.2\(33\)sxj5
CiscoIos12.2\(33\)sxj6

Showing 50 of 1283 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-3204?
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by loading malicious Tcl code on an affected device. A successful exploit could allow the attacker to cause memory corruption or execute the code with root privileges on the underlying OS of the affected device.
How severe is CVE-2020-3204?
CVE-2020-3204 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.38% probability of exploitation in the next 30 days.
How do I fix CVE-2020-3204?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-3204?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST