CVE-2020-3215

A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual appliance (OVA). An attacker could exploit this vulnerability by installing a malicious OVA on an affected device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ciscoCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
ciscoios_xe
3.7.0e:e
ciscoios_xe
3.7.1e:e
ciscoios_xe
3.7.2e:e
ciscoios_xe
3.7.3e:e
ciscoios_xe
3.7.4e:e
ciscoios_xe
3.7.5e:e
ciscoios_xe
3.8.0e:e
ciscoios_xe
3.8.0s:s
ciscoios_xe
3.8.1e:e
ciscoios_xe
3.8.1s:s
ciscoios_xe
3.8.2e:e
ciscoios_xe
3.8.2s:s
ciscoios_xe
3.8.3e:e
ciscoios_xe
3.8.4e:e
ciscoios_xe
3.8.5ae:ae
ciscoios_xe
3.8.5e:e
ciscoios_xe
3.8.6e:e
ciscoios_xe
3.8.7e:e
ciscoios_xe
3.8.8e:e
ciscoios_xe
3.9.0as:as
ciscoios_xe
3.9.0e:e
ciscoios_xe
3.9.0s:s
ciscoios_xe
3.9.1as:as
ciscoios_xe
3.9.1e:e
ciscoios_xe
3.9.1s:s
ciscoios_xe
3.9.2be:be
ciscoios_xe
3.9.2e:e
ciscoios_xe
3.9.2s:s
ciscoios_xe
3.10.0ce:ce
ciscoios_xe
3.10.0e:e
ciscoios_xe
3.10.0s:s
ciscoios_xe
3.10.1ae:ae
ciscoios_xe
3.10.1e:e
ciscoios_xe
3.10.1s:s
ciscoios_xe
3.10.1se:se
ciscoios_xe
3.10.2as:as
ciscoios_xe
3.10.2e:e
ciscoios_xe
3.10.2s:s
ciscoios_xe
3.10.2ts:ts
ciscoios_xe
3.10.3e:e
ciscoios_xe
3.10.3s:s
ciscoios_xe
3.10.4s:s
ciscoios_xe
3.10.5s:s
ciscoios_xe
3.10.6s:s
ciscoios_xe
3.10.7s:s
ciscoios_xe
3.10.8as:as
ciscoios_xe
3.10.8s:s
ciscoios_xe
3.10.9s:s
ciscoios_xe
3.10.10s:s
ciscoios_xe
3.11.0e:e
ciscoios_xe
3.11.0s:s
ciscoios_xe
3.11.1s:s
ciscoios_xe
3.11.2s:s
ciscoios_xe
3.11.3e:e
ciscoios_xe
3.11.3s:s
ciscoios_xe
3.11.4s:s
ciscoios_xe
3.12.0as:as
ciscoios_xe
3.12.0s:s
ciscoios_xe
3.12.1s:s
ciscoios_xe
3.12.2s:s
ciscoios_xe
3.12.3s:s
ciscoios_xe
3.12.4s:s
ciscoios_xe
3.13.0as:as
ciscoios_xe
3.13.0s:s
ciscoios_xe
3.13.1s:s
ciscoios_xe
3.13.2as:as
ciscoios_xe
3.13.2s:s
ciscoios_xe
3.13.3s:s
ciscoios_xe
3.13.4s:s
ciscoios_xe
3.13.5as:as
ciscoios_xe
3.13.5s:s
ciscoios_xe
3.13.6as:as
ciscoios_xe
3.13.6bs:bs
ciscoios_xe
3.13.6s:s
ciscoios_xe
3.13.7as:as
ciscoios_xe
3.13.7s:s
ciscoios_xe
3.13.8s:s
ciscoios_xe
3.13.9s:s
ciscoios_xe
3.13.10s:s
ciscoios_xe
3.14.0s:s
ciscoios_xe
3.14.1s:s
ciscoios_xe
3.14.2s:s
ciscoios_xe
3.14.3s:s
ciscoios_xe
3.14.4s:s
ciscoios_xe
3.15.0s:s
ciscoios_xe
3.15.1cs:cs
ciscoios_xe
3.15.1s:s
ciscoios_xe
3.15.2s:s
ciscoios_xe
3.15.3s:s
ciscoios_xe
3.15.4s:s
ciscoios_xe
3.16.0as:as
ciscoios_xe
3.16.0bs:bs
ciscoios_xe
3.16.0cs:cs
ciscoios_xe
3.16.0s:s
ciscoios_xe
3.16.1as:as
ciscoios_xe
3.16.1s:s
ciscoios_xe
3.16.2as:as
ciscoios_xe
3.16.2bs:bs
ciscoios_xe
3.16.2s:s
ciscoios_xe
3.16.3as:as
ciscoios_xe
3.16.3s:s
ciscoios_xe
3.16.4as:as
ciscoios_xe
3.16.4bs:bs
ciscoios_xe
3.16.4cs:cs
ciscoios_xe
3.16.4ds:ds
ciscoios_xe
3.16.4es:es
ciscoios_xe
3.16.4gs:gs
ciscoios_xe
3.16.4s:s
ciscoios_xe
3.16.5as:as
ciscoios_xe
3.16.5bs:bs
ciscoios_xe
3.16.5s:s
ciscoios_xe
3.16.6bs:bs
ciscoios_xe
3.16.6s:s
ciscoios_xe
3.16.7as:as
ciscoios_xe
3.16.7bs:bs
ciscoios_xe
3.16.7s:s
ciscoios_xe
3.16.8s:s
ciscoios_xe
3.16.9s:s
ciscoios_xe
3.17.0s:s
ciscoios_xe
3.17.1as:as
ciscoios_xe
3.17.1s:s
ciscoios_xe
3.17.2s:s
ciscoios_xe
3.17.3s:s
ciscoios_xe
3.17.4s:s
ciscoios_xe
3.18.0as:as
ciscoios_xe
3.18.0s:s
ciscoios_xe
3.18.0sp:sp
ciscoios_xe
3.18.1asp:asp
ciscoios_xe
3.18.1bsp:bsp
ciscoios_xe
3.18.1csp:csp
ciscoios_xe
3.18.1gsp:gsp
ciscoios_xe
3.18.1hsp:hsp
ciscoios_xe
3.18.1isp:isp
ciscoios_xe
3.18.1s:s
ciscoios_xe
3.18.1sp:sp
ciscoios_xe
3.18.2asp:asp
ciscoios_xe
3.18.2s:s
ciscoios_xe
3.18.2sp:sp
ciscoios_xe
3.18.3asp:asp
ciscoios_xe
3.18.3bsp:bsp
ciscoios_xe
3.18.3s:s
ciscoios_xe
3.18.3sp:sp
ciscoios_xe
3.18.4s:s
ciscoios_xe
3.18.4sp:sp
ciscoios_xe
3.18.5sp:sp
ciscoios_xe
3.18.6sp:sp
ciscoios_xe
16.1.1
ciscoios_xe
16.1.2
ciscoios_xe
16.1.3
ciscoios_xe
16.2.1
ciscoios_xe
16.2.2
ciscoios_xe
16.3.1
ciscoios_xe
16.3.1a:a
ciscoios_xe
16.3.2
ciscoios_xe
16.3.3
ciscoios_xe
16.3.4
ciscoios_xe
16.3.5
ciscoios_xe
16.3.5b:b
ciscoios_xe
16.3.6
ciscoios_xe
16.3.7
ciscoios_xe
16.3.8
ciscoios_xe
16.3.9
ciscoios_xe
16.4.1
ciscoios_xe
16.4.2
ciscoios_xe
16.4.3
ciscoios_xe
16.5.1
ciscoios_xe
16.5.1a:a
ciscoios_xe
16.5.1b:b
ciscoios_xe
16.5.2
ciscoios_xe
16.5.3
ciscoios_xe
16.6.1
ciscoios_xe
16.6.2
ciscoios_xe
16.6.3
ciscoios_xe
16.6.4
ciscoios_xe
16.6.4a:a
ciscoios_xe
16.6.4s:s
ciscoios_xe
16.6.5
ciscoios_xe
16.6.5a:a
ciscoios_xe
16.6.5b:b
ciscoios_xe
16.6.6
ciscoios_xe
16.7.1
ciscoios_xe
16.7.1a:a
ciscoios_xe
16.7.1b:b
ciscoios_xe
16.7.2
ciscoios_xe
16.7.3
ciscoios_xe
16.7.4
ciscoios_xe
16.8.1
ciscoios_xe
16.8.1a:a
ciscoios_xe
16.8.1b:b
ciscoios_xe
16.8.1c:c
ciscoios_xe
16.8.1d:d
ciscoios_xe
16.8.1e:e
ciscoios_xe
16.8.1s:s
ciscoios_xe
16.8.2
ciscoios_xe
16.8.3
ciscoios_xe
16.9.1
ciscoios_xe
16.9.1a:a
ciscoios_xe
16.9.1b:b
ciscoios_xe
16.9.1c:c
ciscoios_xe
16.9.1d:d
ciscoios_xe
16.9.1s:s
ciscoios_xe
16.9.2
ciscoios_xe
16.9.2a:a
ciscoios_xe
16.9.2s:s
ciscoios_xe
16.9.3
ciscoios_xe
16.9.3a:a
ciscoios_xe
16.9.3h:h
ciscoios_xe
16.9.3s:s
ciscoios_xe
16.10.1
ciscoios_xe
16.10.1a:a
ciscoios_xe
16.10.1b:b
ciscoios_xe
16.10.1c:c
ciscoios_xe
16.10.1d:d
ciscoios_xe
16.10.1e:e
ciscoios_xe
16.10.1f:f
ciscoios_xe
16.10.1g:g
ciscoios_xe
16.10.1s:s
ciscoios_xe
16.10.2
ciscoios_xe
16.11.1
ciscoios_xe
16.11.1a:a
ciscoios_xe
16.11.1b:b
ciscoios_xe
16.11.1c:c
ciscoios_xe
16.11.1s:s
ciscoios_xe
16.12.1y:y
𝑥
= Vulnerable software versions