Vulnslist

find the latest Cisco vulnerabilities

Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches Secure Boot Bypass Vulnerability

cisco-sa-c9300-spi-ace-yejYgnNQ · High · Published · Updated

A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to errors that occur when retrieving the public release key that is used for image signature verification. An attacker could exploit this vulnerability by modifying specific variables in the Serial Peripheral Interface (SPI) flash memory of an affected device. A successful exploit could allow the attacker to execute persistent code on the underlying operating system. Note: In Cisco IOS XE Software releases 16.11.1 and later, the complexity of an attack using this vulnerability is high. However, an attacker with level-15 privileges could easily downgrade the Cisco IOS XE Software on a device to a release that would lower the attack complexity. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-c9300-spi-ace-yejYgnNQ

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2023-20082
Cisco Bug IDsCSCwa61120
CVSS ScoreBase 6.1
Base 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco IOS XE ROMMON Software, Cisco IOS XE Software Bootloader (ROMMON)

CSAF Product Statuses

Product Status Source CVE Rows
Cisco IOS XE Software Bootloader (ROMMON) known_affected cisco_csaf CVE-2023-20082 1

Related Products

Product CVE Evidence
Cisco Catalyst 9300 Series Switches CVE-2023-20082 Cisco OpenVuln · family-level
Cisco IOS XE Software CVE-2023-20082 Cisco OpenVuln
Cisco IOS XE Software Bootloader (ROMMON) CVE-2023-20082 Cisco OpenVuln
Cisco IOS CVE-2023-20082 Cisco OpenVuln
Cisco Catalyst 9200 Series Switches CVE-2023-20082 Cisco OpenVuln · software-dependent
Cisco Catalyst 9400 Series Switches CVE-2023-20082 Cisco OpenVuln · software-dependent
Cisco Catalyst 9500 Series Switches CVE-2023-20082 Cisco OpenVuln · software-dependent
Cisco Catalyst 9600 Series Switches CVE-2023-20082 Cisco OpenVuln · software-dependent
Cisco IOS XE ROMMON Software CVE-2023-20082 Cisco OpenVuln
Cisco IOS Software CVE-2023-20082 Cisco OpenVuln