CVE-2020-3141

HIGH

Cisco IOS XE - Privilege Escalation

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0098
EPSS Percentile 77.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (4)
cisco/ios_xe 16.9.4
cisco/ios_xe 17.2.1
cisco/ios_xe 17.3
cisco/ios_xe 17.4.1
Published Sep 24, 2020
Tracked Since Feb 18, 2026