Cisco IOS Software for Cisco Industrial Routers Arbitrary Code Execution Vulnerabilities (cisco-sa-ios-iot-rce-xYRSeMNH)

critical Nessus Plugin ID 139614

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) is affected by multiple arbitrary code execution vulnerabilities, as follows:

- A vulnerability in the area of code that manages inter-VM signaling due to incorrect bounds checking. An unauthenticated, remote attacker can exploit this, by sending malicious packets to an affected device, in order to execute arbitrary code on an affected system or cause the system to crash and reload.
(CVE-2020-3198)

- A vulnerability in one of the diagnostic test CLI commands. This exists because, under specific circumstances, the affected software permits the modification of the device's run-time memory. An authenticated, local attacker can exploit this, by authenticating to the targeted device and issuing a specific diagnostic test command at the CLI in order to execute arbitrary code on an affected device.
(CVE-2020-3258)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in the Cisco bug IDs CSCvr12083 and CSCvr46885

See Also

http://www.nessus.org/u?f0db8a62

http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-73388

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr12083

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr46885

Plugin Details

Severity: Critical

ID: 139614

File Name: cisco-sa-ios-iot-rce-xYRSeMNH-ios.nasl

Version: 1.13

Type: combined

Family: CISCO

Published: 8/17/2020

Updated: 2/26/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2020-3258

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:ios

Required KB Items: Host/Cisco/IOS/Model, Host/Cisco/IOS/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 6/3/2020

Vulnerability Publication Date: 6/3/2020

Reference Information

CVE: CVE-2020-3198, CVE-2020-3258

CWE: 119

CISCO-SA: cisco-sa-ios-iot-rce-xYRSeMNH

IAVA: 2020-A-0239-S

CISCO-BUG-ID: CSCvr12083, CSCvr46885