CVE-2020-3205 is a critical vulnerability in Cisco IOS Software affecting Cisco 809/829 Industrial Integrated Services Routers and CGR1000. It allows an unauthenticated, adjacent attacker to execute arbitrary shell commands on the Virtual Device Server (VDS) with root privileges due to insufficient validation of inter-VM channel signaling packets. This vulnerability carries a CVSSv3.1 score of 8.8 (High), indicating a severe risk with low attack complexity and high impact on confidentiality, integrity, and availability, potentially leading to complete system compromise. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(60\)ez16CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(60\)ez16:*:*:*:*:*:*:* | ||
15.0\(2\)sg11aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.0\(2\)sg11a:*:*:*:*:*:*:* | ||
15.2\(4\)jaz1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(4\)jaz1:*:*:*:*:*:*:* | ||
15.3\(3\)jaa1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3\(3\)jaa1:*:*:*:*:*:*:* | ||
15.3\(3\)jpiCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3\(3\)jpi:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.