CVE-2020-3237

MEDIUM

Cisco IOx < 1.9.0 - Authenticated Arbitrary File Overwrite via Crafted Application Package

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to overwrite arbitrary files in the virtual instance that is running on the affected device. The vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this vulnerability by including a crafted file in an application package. An exploit could allow the attacker to overwrite files.

References (1)

Core 1
Core References

Scores

CVSS v3 6.3
EPSS 0.0005
EPSS Percentile 14.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (1)
cisco/iox < 1.9.0
Published Jun 03, 2020
Tracked Since Feb 18, 2026