7.8
CVSSv3

CVE-2020-3455

Published: 21/10/2020 Updated: 28/10/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local malicious user to bypass the secure boot mechanisms. The vulnerability is due to insufficient protections of the secure boot process. An attacker could exploit this vulnerability by injecting code into a specific file that is then referenced during the device boot process. A successful exploit could allow the malicious user to break the chain of trust and inject code into the boot process of the device which would be executed at each boot and maintain persistence across reboots.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firepower_extensible_operating_system

Vendor Advisories

A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass the secure boot mechanisms The vulnerability is due to insufficient protections of the secure boot process An attacker could exploit this vulnerability by injecting code into a specific file that is then referenced during the ...