8.8
CVSSv3

CVE-2020-3425

Published: 24/09/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios_xe 16.1.1

cisco ios_xe 16.1.2

cisco ios_xe 16.1.3

cisco ios_xe 16.2.1

cisco ios_xe 16.2.2

cisco ios_xe 16.3.1

cisco ios_xe 16.3.1a

cisco ios_xe 16.3.2

cisco ios_xe 16.3.3

cisco ios_xe 16.3.4

cisco ios_xe 16.3.5

cisco ios_xe 16.3.5b

cisco ios_xe 16.3.6

cisco ios_xe 16.3.7

cisco ios_xe 16.3.8

cisco ios_xe 16.3.9

cisco ios_xe 16.3.10

cisco ios_xe 16.4.1

cisco ios_xe 16.4.2

cisco ios_xe 16.4.3

cisco ios_xe 16.5.1

cisco ios_xe 16.5.1a

cisco ios_xe 16.5.1b

cisco ios_xe 16.5.2

cisco ios_xe 16.5.3

cisco ios_xe 16.6.1

cisco ios_xe 16.6.2

cisco ios_xe 16.6.3

cisco ios_xe 16.6.4

cisco ios_xe 16.6.4a

cisco ios_xe 16.6.4s

cisco ios_xe 16.6.5

cisco ios_xe 16.6.5a

cisco ios_xe 16.6.5b

cisco ios_xe 16.6.6

cisco ios_xe 16.6.7

cisco ios_xe 16.6.7a

cisco ios_xe 16.6.8

cisco ios_xe 16.7.1

cisco ios_xe 16.7.1a

cisco ios_xe 16.7.1b

cisco ios_xe 16.7.2

cisco ios_xe 16.7.3

cisco ios_xe 16.7.4

cisco ios_xe 16.8.1

cisco ios_xe 16.8.1a

cisco ios_xe 16.8.1b

cisco ios_xe 16.8.1c

cisco ios_xe 16.8.1d

cisco ios_xe 16.8.1e

cisco ios_xe 16.8.1s

cisco ios_xe 16.8.2

cisco ios_xe 16.8.3

cisco ios_xe 16.9.1

cisco ios_xe 16.9.1a

cisco ios_xe 16.9.1b

cisco ios_xe 16.9.1c

cisco ios_xe 16.9.1d

cisco ios_xe 16.9.1s

cisco ios_xe 16.9.2

cisco ios_xe 16.9.2a

cisco ios_xe 16.9.2s

cisco ios_xe 16.9.3

cisco ios_xe 16.9.3a

cisco ios_xe 16.9.3h

cisco ios_xe 16.9.3s

cisco ios_xe 16.9.4

cisco ios_xe 16.9.4c

cisco ios_xe 16.9.5

cisco ios_xe 16.9.5f

cisco ios_xe 16.10.1

cisco ios_xe 16.10.1a

cisco ios_xe 16.10.1b

cisco ios_xe 16.10.1c

cisco ios_xe 16.10.1d

cisco ios_xe 16.10.1e

cisco ios_xe 16.10.1f

cisco ios_xe 16.10.1g

cisco ios_xe 16.10.1s

cisco ios_xe 16.10.2

cisco ios_xe 16.10.3

cisco ios_xe 16.11.1

cisco ios_xe 16.11.1a

cisco ios_xe 16.11.1b

cisco ios_xe 16.11.1c

cisco ios_xe 16.11.1s

cisco ios_xe 16.11.2

cisco ios_xe 16.12.1

cisco ios_xe 16.12.1a

cisco ios_xe 16.12.1c

cisco ios_xe 16.12.1s

cisco ios_xe 16.12.1t

cisco ios_xe 16.12.1w

cisco ios_xe 16.12.1x

cisco ios_xe 16.12.1y

cisco ios_xe 16.12.2

cisco ios_xe 16.12.2a

cisco ios_xe 16.12.2s

cisco ios_xe 16.12.2t

cisco ios_xe 17.1.1

cisco ios_xe 17.1.1a

cisco ios_xe 17.1.1s

cisco ios_xe 17.1.1t

cisco ios_xe 17.2.1

cisco ios_xe 17.2.1a

cisco ios_xe 17.2.1r

cisco ios_xe 17.2.1v

Vendor Advisories

Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device For more information about these vulnerabilities, see the Details section of this advisory Cisco has released so ...