CVE-2020-3199

HIGH

Cisco IOS - Denial of Service and Remote Code Execution

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0012
EPSS Percentile 30.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (50)
cisco/ios 12.2\(60\)ez16
cisco/ios 15.0\(2\)sg11a
cisco/ios 15.3\(3\)jaa1
cisco/ios 15.3\(3\)jpj
cisco/ios 15.4\(1\)cg
cisco/ios 15.4\(2\)cg
cisco/ios 15.4\(3\)m
cisco/ios 15.4\(3\)m1
cisco/ios 15.4\(3\)m2
cisco/ios 15.4\(3\)m3
... and 40 more
Published Jun 03, 2020
Tracked Since Feb 18, 2026