A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by using a specific command at the command line. A successful exploit could allow the attacker to obtain read-only access to files that are located on the flash: filesystem that otherwise might not have been accessible.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-24748 A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by using a specific command at the command line. A successful exploit could allow the attacker to obtain read-only access to files that are located on the flash: filesystem that otherwise might not have been accessible.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-13T17:58:01.086Z

Reserved: 2019-12-12T00:00:00

Link: CVE-2020-3477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-24T18:15:19.917

Modified: 2024-11-21T05:31:08.990

Link: CVE-2020-3477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses