Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2020-3416 Details

Description

Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenticated, local attacker with high privileges to execute persistent code at bootup and break the chain of trust. These vulnerabilities are due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set. An attacker could exploit these vulnerabilities by copying a specific file to the local file system of an affected device and defining specific ROMMON variables. A successful exploit could allow the attacker to run arbitrary code on the underlying operating system (OS) with root privileges. To exploit these vulnerabilities, an attacker would need to have access to the root shell on the device or have physical access to the device.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-94Improper Control of Generation of Code ('Code Injection')[email protected]
CWE-749Exposed Dangerous Method or Function[email protected]

Affected Products

ProductVersions
cisco ios xe
16.12.1
17.2

CPE

  • cpe:2.3:o:cisco:ios_xe:16.12.1:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:ios_xe:17.2:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco asr 902
All versions

CPE

  • cpe:2.3:h:cisco:asr_902:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco asr 903
All versions

CPE

  • cpe:2.3:h:cisco:asr_903:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco asr 907
All versions

CPE

  • cpe:2.3:h:cisco:asr_907:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

7 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2020-3416
NVD Published Date:
Sep 24, 2020
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2020-3416 Details - Not Deferred