Cisco this week announced that it has patched tens of vulnerabilities in its IOS software, including a dozen security flaws that impact the company’s industrial routers and switches.
The networking giant on June 3 published its semiannual bundled publication of security advisories for IOS and IOS XE software. The advisories describe 25 vulnerabilities that have been rated critical or high severity. In addition, the company has published tens of other advisories for high- and medium-severity issues affecting IOS and other software.
A dozen vulnerabilities appear to impact the company’s industrial products. One of the security bugs rated critical is CVE-2020-3205, which allows an unauthenticated attacker with network access to execute arbitrary shell commands on the virtual device server of affected devices.
An attacker can exploit the vulnerability by sending specially crafted packets to the targeted device, and successful exploitation could lead to the system getting completely compromised.
The vulnerability tracked as CVE-2020-3198 has also been rated critical. It can allow a remote, unauthenticated attacker to execute arbitrary code on the system or cause it to crash and reload by sending it malicious packets.
Both these critical weaknesses impact Cisco 809 and 829 industrial integrated services routers (ISR) and 1000 series connected grid routers (CGR).
The high-severity flaws affecting industrial networking devices can be exploited to escalate privileges using hardcoded credentials, cause a DoS condition by sending specially crafted CIP (Common Industrial Protocol) traffic, execute arbitrary shell commands, and boot malicious software images. However, for these vulnerabilities exploitation requires authentication, local access, or a feature that is disabled by default to be enabled.
Some of the high-severity vulnerabilities affecting industrial products are related to the IOx application environment. They allow attackers to write or modify arbitrary files, launch DoS attacks, or execute arbitrary code with elevated privileges.
Learn more about vulnerabilities in industrial systems at SecurityWeek’s 2020 ICS Cyber Security Conference and SecurityWeek’s Security Summits virtual event series
The medium-severity vulnerabilities affecting Cisco’s industrial products can be exploited by authenticated attackers for cross-site scripting (XSS) attacks and to overwrite arbitrary files.
The list of industrial Cisco products impacted by these vulnerabilities include 800, 809 and 829 series industrial ISRs, 1000 series CGR, the IC3000 Industrial Compute Gateway, Industrial Ethernet (IE) 4000 series switches, Catalyst IE3400 rugged series switches, and IR510 WPAN routers. Most of the vulnerabilities only impact 809 and 829 series industrial ISRs and 1000 series CGR devices.
The vendor also informed customers that its IOx application hosting infrastructure for IOS XE software is affected by a critical vulnerability that can be exploited by a remote, unauthenticated attacker to execute IOx API commands.
Cisco says it has found no evidence that these vulnerabilities have been exploited in attacks.
Related: IP-in-IP Vulnerability Affects Devices From Cisco and Others

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- Intel Boasts Attack Surface Reduction With New 13th Gen Core vPro Platform
- Dole Says Employee Information Compromised in Ransomware Attack
- High-Severity Vulnerabilities Found in WellinTech Industrial Data Historian
- CISA Expands Cybersecurity Committee, Updates Baseline Security Goals
- Exploitation of 55 Zero-Day Vulnerabilities Came to Light in 2022: Mandiant
- Organizations Notified of Remotely Exploitable Vulnerabilities in Aveva HMI, SCADA Products
- Waterfall Security, TXOne Networks Launch New OT Security Appliances
- Hitachi Energy Blames Data Breach on Zero-Day as Ransomware Gang Threatens Firm
Latest News
- Intel Co-founder, Philanthropist Gordon Moore Dies at 94
- Google Leads $16 Million Investment in Dope.security
- US Charges 20-Year-Old Head of Hacker Site BreachForums
- Tesla Hacked Twice at Pwn2Own Exploit Contest
- CISA Ships ‘Untitled Goose Tool’ to Hunt for Microsoft Azure Cloud Infections
- Critical WooCommerce Payments Vulnerability Leads to Site Takeover
- PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw
- CISA Gets Proactive With New Pre-Ransomware Alerts
