CVE-2020-3208 is a medium-severity vulnerability affecting Cisco IOS Software on Cisco 809 and 829 Industrial Integrated Services Routers. It allows an authenticated, local attacker with privilege level 15 credentials to disable image verification and boot a malicious software image. The attack requires initial authentication and access to the Virtual Device Server (VDS) shell. While the CVSS score is 6.7, indicating high impact on confidentiality, integrity, and availability, the exploit complexity is low. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(60\)ez16CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(60\)ez16:*:*:*:*:*:*:* | ||
15.0\(2\)sg11aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.0\(2\)sg11a:*:*:*:*:*:*:* | ||
15.3\(3\)jaa1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3\(3\)jaa1:*:*:*:*:*:*:* | ||
15.3\(3\)jpjCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3\(3\)jpj:*:*:*:*:*:*:* | ||
15.5\(3\)m0aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(3\)m0a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.