CVE-2020-3219

HIGH

Cisco IOS XE - Authenticated Remote Code Execution via Web UI Input Validation Bypass

Title source: llm
STIX 2.1

Description

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of user-supplied input to the web UI. An attacker could exploit this vulnerability by submitting crafted input to the web UI. A successful exploit could allow an attacker to execute arbitrary commands with administrative privileges on an affected device.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0047
EPSS Percentile 64.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-77
Status published
Products (50)
cisco/ios_xe 16.1.1
cisco/ios_xe 16.1.2
cisco/ios_xe 16.1.3
cisco/ios_xe 16.2.1
cisco/ios_xe 16.2.2
cisco/ios_xe 16.3.1
cisco/ios_xe 16.3.1a
cisco/ios_xe 16.3.2
cisco/ios_xe 16.3.3
cisco/ios_xe 16.3.4
... and 40 more
Published Jun 03, 2020
Tracked Since Feb 18, 2026