CVE-2020-3524 describes a vulnerability in Cisco IOS XE ROM Monitor (ROMMON) Software affecting Cisco 4000 Series, ASR 920 Series, ASR 1000 Series, and cBR-8 Routers. An unauthenticated, physical attacker can exploit a debugging configuration option by forcing the device into ROMMON mode via console access. This allows the attacker to break the chain of trust and load an unsigned, compromised software image. The vulnerability has a CVSS score of 6.8 (Medium), indicating high impact on confidentiality, integrity, and availability with physical access and low attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.2\(1r\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe_rom_monitor:*:*:*:*:*:*:*:* | ||
< 15.6\(18r\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe_rom_monitor:*:*:*:*:*:*:*:* | ||
< 16.4\(1r\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe_rom_monitor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.