CVE-2020-3425: Cisco IOS XE
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected products
- Cisco IOS XE: version 16.1.1 only; version 16.1.2 only; version 16.1.3 only; version 16.2.1 only; version 16.2.2 only; version 16.3.1 only; …
Published 2020-09-24. Last modified 2026-06-17.