CVE-2020-3209
Last modified
CVE-2020-3209 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability is due to an improper check on the area of code that manages the verification of the digital signatures of system image files during the initial boot process. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability is due to an improper check on the area of code that manages the verification of the digital signatures of system image files during the initial boot process. An attacker could exploit this vulnerability by loading unsigned software on an affected device. A successful exploit could allow the attacker to install and boot a malicious software image or execute unsigned binaries on the targeted device.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.2.0se |
| Cisco | Ios Xe | 3.2.0sg |
| Cisco | Ios Xe | 3.2.1se |
| Cisco | Ios Xe | 3.2.1sg |
| Cisco | Ios Xe | 3.2.2se |
| Cisco | Ios Xe | 3.2.2sg |
| Cisco | Ios Xe | 3.2.3se |
| Cisco | Ios Xe | 3.2.3sg |
| Cisco | Ios Xe | 3.2.4sg |
| Cisco | Ios Xe | 3.2.5sg |
| Cisco | Ios Xe | 3.2.6sg |
| Cisco | Ios Xe | 3.2.7sg |
| Cisco | Ios Xe | 3.2.8sg |
| Cisco | Ios Xe | 3.2.9sg |
| Cisco | Ios Xe | 3.2.10sg |
| Cisco | Ios Xe | 3.2.11sg |
| Cisco | Ios Xe | 3.3.0se |
| Cisco | Ios Xe | 3.3.0sg |
| Cisco | Ios Xe | 3.3.0sq |
| Cisco | Ios Xe | 3.3.0xo |
| Cisco | Ios Xe | 3.3.1se |
| Cisco | Ios Xe | 3.3.1sg |
| Cisco | Ios Xe | 3.3.1sq |
| Cisco | Ios Xe | 3.3.1xo |
| Cisco | Ios Xe | 3.3.2se |
| Cisco | Ios Xe | 3.3.2sg |
| Cisco | Ios Xe | 3.3.2xo |
| Cisco | Ios Xe | 3.3.3se |
| Cisco | Ios Xe | 3.3.4se |
| Cisco | Ios Xe | 3.3.5se |
| Cisco | Ios Xe | 3.4.0sg |
| Cisco | Ios Xe | 3.4.0sq |
| Cisco | Ios Xe | 3.4.1sg |
| Cisco | Ios Xe | 3.4.1sq |
| Cisco | Ios Xe | 3.4.2sg |
| Cisco | Ios Xe | 3.4.3sg |
| Cisco | Ios Xe | 3.4.4sg |
| Cisco | Ios Xe | 3.4.5sg |
| Cisco | Ios Xe | 3.4.6sg |
| Cisco | Ios Xe | 3.4.7sg |
| Cisco | Ios Xe | 3.4.8sg |
| Cisco | Ios Xe | 3.5.0e |
| Cisco | Ios Xe | 3.5.0sq |
| Cisco | Ios Xe | 3.5.1e |
| Cisco | Ios Xe | 3.5.1sq |
| Cisco | Ios Xe | 3.5.2e |
| Cisco | Ios Xe | 3.5.2sq |
| Cisco | Ios Xe | 3.5.3e |
| Cisco | Ios Xe | 3.5.3sq |
| Cisco | Ios Xe | 3.5.4sq |
Showing 50 of 314 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-3209?
How severe is CVE-2020-3209?
How do I fix CVE-2020-3209?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-3203A vulnerability in the locally significant certificate (LSC)…8.6
- CVE-2020-3204A vulnerability in the Tool Command Language (Tcl) interpret…6.7
- CVE-2020-3205A vulnerability in the implementation of the inter-VM channe…8.8
- CVE-2020-3206A vulnerability in the handling of IEEE 802.11w Protected Ma…4.7
- CVE-2020-3207A vulnerability in the processing of boot options of specifi…6.7
- CVE-2020-3208A vulnerability in the image verification feature of Cisco I…6.7
- CVE-2020-3210A vulnerability in the CLI parsers of Cisco IOS Software for…6.7
- CVE-2020-3211A vulnerability in the web UI of Cisco IOS XE Software could…7.2
- CVE-2020-3212A vulnerability in the web UI of Cisco IOS XE Software could…7.2
- CVE-2020-3213A vulnerability in the ROMMON of Cisco IOS XE Software could…6.7
- CVE-2020-3214A vulnerability in Cisco IOS XE Software could allow an auth…6.7
- CVE-2020-3215A vulnerability in the Virtual Services Container of Cisco I…6.7
Are you affected by CVE-2020-3209?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
