CVE-2020-3524 (CNNVD-202009-1453)
中文标题:
Cisco IOS XE ROM监控器和Cisco ASR 920 和 Cisco ASR 1000 访问控制错误漏洞
英文标题:
Cisco IOS XE ROM Monitor Software Vulnerability
漏洞描述
中文描述:
Cisco IOS等都是美国思科(Cisco)公司的产品。Cisco IOS是一套为其网络设备开发的操作系统。IOS XE是一套为其网络设备开发的操作系统。ASR 1000 Series Aggregation Services Routers是一款企业级聚合服务路由器。 Cisco IOS XE ROM监控器(ROMMON) Cisco 4000系列版本,Cisco ASR 920系列版本,Cisco ASR 1000系列版本,Cisco cBR-8 Converged Broadband Routers版本 中存在安全漏洞,该漏洞源于受影响的软件中存在调试配置选项所致,该漏洞允许攻击者通过控制台连接到受影响的设备,将设备强制为ROMMON模式,并使用该设备上的特定选项编写恶意模式,从而利用此漏洞。
英文描述:
A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cisco ASR 920 Series Aggregation Services Routers, Cisco ASR 1000 Series Aggregation Services Routers, and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to break the chain of trust and load a compromised software image on an affected device. The vulnerability is due to the presence of a debugging configuration option in the affected software. An attacker could exploit this vulnerability by connecting to an affected device through the console, forcing the device into ROMMON mode, and writing a malicious pattern using that specific option on the device. A successful exploit could allow the attacker to break the chain of trust and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco IOS XE ROMMON Software | n/a | - | - |
cpe:2.3:a:cisco:cisco_ios_xe_rommon_software:n_a:*:*:*:*:*:*:*
|
| cisco | ios_xe_rom_monitor | * | - | - |
cpe:2.3:o:cisco:ios_xe_rom_monitor:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-3524 |
2025-11-11 15:20:37 | 2025-11-11 07:36:19 |
| NVD | nvd_CVE-2020-3524 |
2025-11-11 14:57:03 | 2025-11-11 07:44:43 |
| CNNVD | cnnvd_CNNVD-202009-1453 |
2025-11-11 15:10:30 | 2025-11-11 07:56:26 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-202009-1453
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']