Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2020-3208

A vulnerability in the image verification feature of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) could allow an authenticated, local attacker to boot a malicious software image on an affected device. The vulnerability is due to insufficient access restrictions on the area of code that manages the image verification feature. An attacker could exploit this vulnerability by first authenticating to the targeted device and then logging in to the Virtual Device Server (VDS) of an affected device. The attacker could then, from the VDS shell, disable Cisco IOS Software integrity (image) verification. A successful exploit could allow the attacker to boot a malicious Cisco IOS Software image on the targeted device. To exploit this vulnerability, the attacker must have valid user credentials at privilege level 15.

  • Published: Jun 3, 2020
  • Updated: Apr 14, 2023
  • CVE: CVE-2020-3208
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.7
  • AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.2
  • AV:L/AC:L/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
cisco / ios 12.2(60)ez16 12.2(60)ez16.x
cisco / ios 15.0(2)sg11a 15.0(2)sg11a.x
cisco / ios 15.3(3)jaa1 15.3(3)jaa1.x
cisco / ios 15.3(3)jpj 15.3(3)jpj.x
cisco / ios 15.5(3)m0a 15.5(3)m0a.x
cisco / ios 15.5(3)m1 15.5(3)m1.x
cisco / ios 15.5(3)m2 15.5(3)m2.x
cisco / ios 15.5(3)m2a 15.5(3)m2a.x
cisco / ios 15.5(3)m3 15.5(3)m3.x
cisco / ios 15.5(3)m4 15.5(3)m4.x
cisco / ios 15.5(3)m4a 15.5(3)m4a.x
cisco / ios 15.5(3)m5 15.5(3)m5.x
cisco / ios 15.5(3)m6 15.5(3)m6.x
cisco / ios 15.5(3)m6a 15.5(3)m6a.x
cisco / ios 15.5(3)m7 15.5(3)m7.x
cisco / ios 15.5(3)m8 15.5(3)m8.x
cisco / ios 15.5(3)m9 15.5(3)m9.x
cisco / ios 15.5(3)m10 15.5(3)m10.x
cisco / ios 15.5(3)m11 15.5(3)m11.x
cisco / ios 15.6(1)t 15.6(1)t.x
cisco / ios 15.6(1)t0a 15.6(1)t0a.x
cisco / ios 15.6(1)t1 15.6(1)t1.x
cisco / ios 15.6(1)t2 15.6(1)t2.x
cisco / ios 15.6(1)t3 15.6(1)t3.x
cisco / ios 15.6(3)m 15.6(3)m.x
cisco / ios 15.6(3)m0a 15.6(3)m0a.x
cisco / ios 15.6(3)m1 15.6(3)m1.x
cisco / ios 15.6(3)m1b 15.6(3)m1b.x
cisco / ios 15.6(3)m2 15.6(3)m2.x
cisco / ios 15.6(3)m3 15.6(3)m3.x
cisco / ios 15.6(3)m3a 15.6(3)m3a.x
cisco / ios 15.6(3)m4 15.6(3)m4.x
cisco / ios 15.6(3)m5 15.6(3)m5.x
cisco / ios 15.6(3)m6 15.6(3)m6.x
cisco / ios 15.6(3)m6a 15.6(3)m6a.x
cisco / ios 15.6(3)m6b 15.6(3)m6b.x
cisco / ios 15.6(3)m7 15.6(3)m7.x
cisco / ios 15.6(3)m8 15.6(3)m8.x
cisco / ios 15.6(3)m9 15.6(3)m9.x
cisco / ios 15.7(3)m 15.7(3)m.x
cisco / ios 15.7(3)m1 15.7(3)m1.x
cisco / ios 15.7(3)m2 15.7(3)m2.x
cisco / ios 15.7(3)m3 15.7(3)m3.x
cisco / ios 15.7(3)m4 15.7(3)m4.x
cisco / ios 15.7(3)m4a 15.7(3)m4a.x
cisco / ios 15.7(3)m4b 15.7(3)m4b.x
cisco / ios 15.7(3)m5 15.7(3)m5.x
cisco / ios 15.7(3)m6 15.7(3)m6.x
cisco / ios 15.7(3)m7 15.7(3)m7.x
cisco / ios 15.8(3)m 15.8(3)m.x
cisco / ios 15.8(3)m0a 15.8(3)m0a.x
cisco / ios 15.8(3)m1 15.8(3)m1.x
cisco / ios 15.8(3)m2 15.8(3)m2.x
cisco / ios 15.8(3)m2a 15.8(3)m2a.x
cisco / ios 15.8(3)m3 15.8(3)m3.x
cisco / ios 15.8(3)m4 15.8(3)m4.x
cisco / ios 15.8(3)m5 15.8(3)m5.x