HIGH · 7.8

CVE-2020-3473

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative contr...

Vulnerability Description

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device. The vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker could exploit this vulnerability by first authenticating to the local CLI shell on the device and using the CLI command to bypass the task group–based checks. A successful exploit could allow the attacker to elevate privileges and perform actions on the device without authorization checks.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos Xr>= 5.0.0, < 7.0.12
Cisco8201-
Cisco8202-
Cisco8808-
Cisco8812-
Cisco8818-
CiscoIos Xrv 9000-
CiscoNcs 540-
CiscoNcs 5501-
CiscoNcs 5501-Se-
CiscoNcs 5502-
CiscoNcs 5502-Se-
CiscoNcs 5508-
CiscoNcs 5516-
CiscoNcs 560-
CiscoNcs 6000-
CiscoNcs 6008-
CiscoNcs 4009-
CiscoNcs 4016-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-3473?

CVE-2020-3473 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative contr...

How severe is CVE-2020-3473?

CVE-2020-3473 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-3473?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xr, Cisco 8201, Cisco 8202, Cisco 8808, Cisco 8812.