CVE-2020-3284 is a critical vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software, allowing unauthenticated, remote attackers to execute unsigned code during the PXE boot process. The vulnerability stems from insufficient verification of internal commands during software image loading, affecting Cisco IOS XR devices. With a CVSS score of 9.8 (Critical), exploitation requires compromising or impersonating the PXE boot server to deliver a malicious image, leading to full compromise (confidentiality, integrity, availability). There is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.65CPE matchmatch criteria | cpe:2.3:o:cisco:a9k-rsp880-se_firmware:*:*:*:*:*:*:*:* | ||
< 6.5.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* | ||
< 10.65CPE matchmatch criteria | cpe:2.3:o:cisco:a9k-rsp880-tr_firmware:*:*:*:*:*:*:*:* | ||
< 14.35CPE matchmatch criteria | cpe:2.3:o:cisco:a99-rp2-se_firmware:*:*:*:*:*:*:*:* | ||
< 14.35CPE matchmatch criteria | cpe:2.3:o:cisco:a99-rp2-tr_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.