CVE-2020-3234
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
03/06/2020
Last modified:
10/06/2020
Description
A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated but low-privileged, local attacker to log in to the Virtual Device Server (VDS) of an affected device by using a set of default credentials. The vulnerability is due to the presence of weak, hard-coded credentials. An attacker could exploit this vulnerability by authenticating to the targeted device and then connecting to VDS through the device’s virtual console by using the static credentials. A successful exploit could allow the attacker to access the Linux shell of VDS as the root user.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:cisco:ios:12.2\(60\)ez16:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.0\(2\)sg11a:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.3\(3\)jaa1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.3\(3\)jpj:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(1\)cg:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(2\)cg:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m3:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m4:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m5:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m6:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m6a:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.4\(3\)m7:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page