CVE-2020-3503

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Sep 24, 2020
Updated: Dec 19, 2024
CWE ID 732
CWE ID 284

Summary

CVE-2020-3503 is a vulnerability affecting the file system permissions in Cisco IOS XE Software. An authenticated, local attacker can exploit this issue to gain read and write access to critical configuration or system files, bypassing normal access restrictions. This vulnerability arises due to insufficient file system permissions on the affected device. An attacker could exploit this flaw by connecting to the guest shell of an affected device and accessing or modifying restricted files. Successful exploitation allows the attacker to view or modify restricted information or configurations that are typically inaccessible to administrators.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco IOS-XE

Affected Vendors

  • Cisco Systems Inc