CVE Feed

    Dashboard / CVE / CVE-2020-3524

    CVE-2020-3524

    A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cisco ASR 920 Series Aggregation Services Routers, Cisco ASR 1000 Series Aggregation Services Routers, and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to break the chain of trust and load a compromised software image on an affected device. The vulnerability is due to the presence of a debugging configuration option in the affected software. An attacker could exploit this vulnerability by connecting to an affected device through the console, forcing the device into ROMMON mode, and writing a malicious pattern using that specific option on the device. A successful exploit could allow the attacker to break the chain of trust and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco.

    Published:Sep 24, 2020
    Last Modified:Nov 21, 2024
    EPS:Sep 24, 2020
    EPSS Score:0.00072
    CVSS Score:6.8

    Affected Products

    Vendor
    Cisco
    Product
    4221 Integrated Services Router
    Vendor
    Cisco
    Product
    4331 Integrated Services Router
    Vendor
    Cisco
    Product
    4431 Integrated Services Router
    Vendor
    Cisco
    Product
    4461 Integrated Services Router
    Vendor
    Cisco
    Product
    Asr-920-10sz-pd
    Vendor
    Cisco
    Product
    Asr-920-12cz-a
    Vendor
    Cisco
    Product
    Asr-920-12cz-d
    Vendor
    Cisco
    Product
    Asr-920-12sz-a
    Vendor
    Cisco
    Product
    Asr-920-12sz-d
    Vendor
    Cisco
    Product
    Asr-920-20sz-m
    Vendor
    Cisco
    Product
    Asr-920-24sz-im
    Vendor
    Cisco
    Product
    Asr-920-24sz-m
    Vendor
    Cisco
    Product
    Asr-920-24tz-m
    Vendor
    Cisco
    Product
    Asr-920-4sz-a
    Vendor
    Cisco
    Product
    Asr-920-4sz-d
    Vendor
    Cisco
    Product
    Asr 1000-x
    Vendor
    Cisco
    Product
    Asr 1001
    Vendor
    Cisco
    Product
    Asr 1001-x
    Vendor
    Cisco
    Product
    Asr 1002
    Vendor
    Cisco
    Product
    Asr 1002-x
    Vendor
    Cisco
    Product
    Asr 1004
    Vendor
    Cisco
    Product
    Asr 1006
    Vendor
    Cisco
    Product
    Asr 1013
    Vendor
    Cisco
    Product
    Asr 920u-12sz-im
    Vendor
    Cisco
    Product
    Cbr8
    Vendor
    Cisco
    Product
    Ios Xe Rom Monitor

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High