CVE-2020-3396
Summary
| CVE | CVE-2020-3396 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-24 18:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections. The vulnerability occurs because the USB 3.0 SSD control data is not stored on the internal boot flash. An attacker could exploit this vulnerability by removing the USB 3.0 SSD, modifying or deleting files on the USB 3.0 SSD by using another device, and then reinserting the USB 3.0 SSD on the original device. A successful exploit could allow the attacker to remove container protections and perform file actions outside the namespace of the container with root privileges. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 1100-4gltegb Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1100-4gltena Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1100-4g Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1100-6g Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1100-lte Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1100 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4321/k9-rf Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4321/k9-ws Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4321/k9 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4331/k9-rf Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4331/k9-ws Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4331/k9 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4351/k9-rf Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4351/k9-ws Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4351/k9 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | Asr 1000-x | - | All | All | All |
| Hardware | Cisco | Asr 1000-x | - | All | All | All |
| Hardware | Cisco | Asr 1001 | - | All | All | All |
| Hardware | Cisco | Asr 1001 | - | All | All | All |
| Hardware | Cisco | Asr 1001-x | - | All | All | All |
| Hardware | Cisco | Asr 1001-x | - | All | All | All |
| Hardware | Cisco | Asr 1002 | - | All | All | All |
| Hardware | Cisco | Asr 1002 | - | All | All | All |
| Hardware | Cisco | Asr 1002-x | - | All | All | All |
| Hardware | Cisco | Asr 1002-x | - | All | All | All |
| Hardware | Cisco | Asr 1004 | - | All | All | All |
| Hardware | Cisco | Asr 1004 | - | All | All | All |
| Hardware | Cisco | Asr 1006 | - | All | All | All |
| Hardware | Cisco | Asr 1006 | - | All | All | All |
| Hardware | Cisco | Asr 1013 | - | All | All | All |
| Hardware | Cisco | Asr 1013 | - | All | All | All |
| Hardware | Cisco | Asr 1023 | - | All | All | All |
| Hardware | Cisco | Asr 1023 | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24p | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24p | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24s | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24s | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24t | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24t | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24u | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24u | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24ux | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-24ux | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48p | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48p | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48s | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48s | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48t | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48t | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48u | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48u | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48un | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48un | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48uxm | - | All | All | All |
| Hardware | Cisco | Catalyst C9300-48uxm | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-24p-4g | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-24p-4g | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-24p-4x | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-24p-4x | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-24t-4g | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-24t-4g | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-24t-4x | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-24t-4x | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-48p-4g | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-48p-4g | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-48p-4x | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-48p-4x | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-48t-4g | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-48t-4g | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-48t-4x | - | All | All | All |
| Hardware | Cisco | Catalyst C9300l-48t-4x | - | All | All | All |
| Hardware | Cisco | Catalyst C9404r | - | All | All | All |
| Hardware | Cisco | Catalyst C9404r | - | All | All | All |
| Hardware | Cisco | Catalyst C9407r | - | All | All | All |
| Hardware | Cisco | Catalyst C9407r | - | All | All | All |
| Hardware | Cisco | Catalyst C9410r | - | All | All | All |
| Hardware | Cisco | Catalyst C9410r | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-12q | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-12q | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-16x | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-16x | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-24q | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-24q | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-24y4c | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-24y4c | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-32c | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-32c | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-32qc | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-32qc | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-40x | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-40x | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-48y4c | - | All | All | All |
| Hardware | Cisco | Catalyst C9500-48y4c | - | All | All | All |
| Hardware | Cisco | Csr1000v | - | All | All | All |
| Hardware | Cisco | Csr1000v | - | All | All | All |
| Operating System | Cisco | Ios Xe | 16.12.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.12.1 | All | All | All |
| Hardware | Cisco | Isr1100 | - | All | All | All |
| Hardware | Cisco | Isr1100 | - | All | All | All |
| Hardware | Cisco | Isr1100-4g | - | All | All | All |
| Hardware | Cisco | Isr1100-4g | - | All | All | All |
| Hardware | Cisco | Isr1100-4gltegb | - | All | All | All |
| Hardware | Cisco | Isr1100-4gltegb | - | All | All | All |
| Hardware | Cisco | Isr1100-4gltena | - | All | All | All |
| Hardware | Cisco | Isr1100-4gltena | - | All | All | All |
| Hardware | Cisco | Isr1100-6g | - | All | All | All |
| Hardware | Cisco | Isr1100-6g | - | All | All | All |
| Hardware | Cisco | Isr1100-lte | - | All | All | All |
| Hardware | Cisco | Isr1100-lte | - | All | All | All |
| Hardware | Cisco | Isr4321/k9 | - | All | All | All |
| Hardware | Cisco | Isr4321/k9 | - | All | All | All |
| Hardware | Cisco | Isr4321/k9-rf | - | All | All | All |
| Hardware | Cisco | Isr4321/k9-rf | - | All | All | All |
| Hardware | Cisco | Isr4321/k9-ws | - | All | All | All |
| Hardware | Cisco | Isr4321/k9-ws | - | All | All | All |
| Hardware | Cisco | Isr4331/k9 | - | All | All | All |
| Hardware | Cisco | Isr4331/k9 | - | All | All | All |
| Hardware | Cisco | Isr4331/k9-rf | - | All | All | All |
| Hardware | Cisco | Isr4331/k9-rf | - | All | All | All |
| Hardware | Cisco | Isr4331/k9-ws | - | All | All | All |
| Hardware | Cisco | Isr4331/k9-ws | - | All | All | All |
| Hardware | Cisco | Isr4351/k9 | - | All | All | All |
| Hardware | Cisco | Isr4351/k9 | - | All | All | All |
| Hardware | Cisco | Isr4351/k9-rf | - | All | All | All |
| Hardware | Cisco | Isr4351/k9-rf | - | All | All | All |
| Hardware | Cisco | Isr4351/k9-ws | - | All | All | All |
| Hardware | Cisco | Isr4351/k9-ws | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS XE Software IOx Guest Shell USB SSD Namespace Protection Privilege Escalation Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.