CVE-2020-3476

MEDIUM

Cisco IOS XE - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying host file system. The vulnerability is due to insufficient validation of the parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing that command with specific parameters. A successful exploit could allow the attacker to overwrite the content of any arbitrary file that resides on the underlying host file system.

References (1)

Core 1
Core References

Scores

CVSS v3 6.0
EPSS 0.0006
EPSS Percentile 20.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (2)
cisco/ios 16.9
cisco/ios 16.10.1
Published Sep 24, 2020
Tracked Since Feb 18, 2026