Vulnslist

find the latest Cisco vulnerabilities

Cisco IOS XR Authenticated User Privilege Escalation Vulnerability

cisco-sa-iosxr-cli-privescl-sDVEmhqv · High · Published · Updated

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though administrative privileges should be required. The attacker must have valid credentials on the affected device. The vulnerability is due to incorrect mapping in the source code of task group assignments for a specific command. An attacker could exploit this vulnerability by issuing the command, which they should not be authorized to issue, on an affected device. A successful exploit could allow the attacker to invalidate the integrity of the disk and cause the device to restart. This vulnerability could allow a user with read permissions to issue a specific command that should require Administrator privileges. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-cli-privescl-sDVEmhqv

Workarounds

Workarounds exist only for devices that have TACACS+ authentication, authorization, and accounting (AAA) command authorization configured. Administrators can use this feature to give nonadministrative users access to the commands that they require and deny access to all other commands.

For more information about Cisco IOS XR task groups and AAA, see ASR9000/XR Using Task groups and understanding Priv levels and authorization https://community.cisco.com/t5/service-providers-documents/asr9000-xr-using-task-groups-and-understanding-priv-levels-and/ta-p/3109596 .

CVEsCVE-2020-3530
Cisco Bug IDsCSCvu79978, CSCvu99038, CSCvv05925
CVSS ScoreBase 8.4
Base 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco IOS XR Software

CSAF Product Statuses

Product Status Source CVE Rows
Cisco IOS XR Software known_affected cisco_csaf CVE-2020-3530 1

Related Products

Product CVE Evidence
Cisco IOS XR Software CVE-2020-3530 Cisco OpenVuln
Cisco IOS CVE-2020-3530 Cisco OpenVuln
Cisco IOS Software CVE-2020-3530 Cisco OpenVuln