Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Cisco’s June 3, 2020 security advisories covered a group of vulnerabilities across industrial networking products—not twelve flaws in every router. The two critical issues highlighted in contemporaneous reporting, CVE-2020-3205 and CVE-2020-3198, could allow remote code or shell-command execution, while the applicable models and fixes vary by CVE. Administrators should match each device’s exact model and software release to Cisco’s individual advisory before planning an update.

What Cisco’s June 2020 advisory batch covered

Cisco published bundled IOS and IOS XE security advisories on June 3, 2020. SecurityWeek reported a dozen vulnerabilities affecting industrial products within a wider publication covering 25 critical- or high-severity IOS and IOS XE vulnerabilities. The industrial issues spanned routers, switches, gateways, and wireless personal area network (WPAN) equipment; the report said most affected the 809/829 industrial ISR families and 1000 Series Connected Grid Routers. SecurityWeek’s June 4, 2020 report describes the broader product group.

That headline does not mean every affected device had all twelve vulnerabilities. A product family’s appearance in the broader report is not enough to establish whether a particular model or software release is affected; check the Cisco advisory for each CVE.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which industrial products were identified?

The Cyber Security Agency of Singapore (CSA) specifically names the following products for CVE-2020-3205, CVE-2020-3198, and CVE-2020-3258:

#1 Best Overall
Cisco 3000 Network Security/Firewall Appliance
  • 2 X 10/100/1000 + 2 X GIGABIT SFP
  • CHASIS 64 GB MSATA
  • DC POWER
  • DIN RAIL MOUNTABLE
  • INDUSTRIAL SECURITY APPLIANCE
  • Cisco 809 and 829 Industrial Integrated Services Routers (ISRs)
  • Cisco 1000 Series Connected Grid Routers (CGRs)

SecurityWeek’s broader account of the industrial vulnerability set also lists 800 Series industrial ISRs, the IC3000 Industrial Compute Gateway, Industrial Ethernet 4000 Series switches, Catalyst IE3400 rugged switches, and IR510 WPAN routers. These broader listings do not establish that every listed family is affected by each CVE. Use the product and release information in the individual Cisco advisory to determine applicability. The CSA alert provides its affected-product scope for the CVEs it covers: CSA alert AL-2020-040.

What the highlighted vulnerabilities could do

CVE Reported issue and potential impact CVSS score
CVE-2020-3205 Insufficient validation of signaling packets sent to the Virtual Device Server. SecurityWeek reported that an unauthenticated attacker with network access could send specially crafted packets and execute arbitrary shell commands on that server. 8.8 (CSA, 2020)
CVE-2020-3198 Incorrect bounds checking of packet values sent to UDP port 9700. Malicious packets could enable remote unauthenticated code execution or cause the device to crash and reload. 9.8 (CSA, 2020)
CVE-2020-3258 Affected software permits modification of device runtime memory. 9.8 (CSA, 2020)

The CSA describes these three CVEs as affecting Cisco 809/829 industrial ISRs and 1000 Series CGRs. The impact descriptions and scores above are from the CSA’s 2020 alert and SecurityWeek’s contemporaneous reporting; consult Cisco’s advisory for the detailed technical conditions for a deployed device.

Rank #2
Cisco Secure Firewall 1210 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN
  • Functionality: Centralized Management
  • Firewall Protection Supported: Enterprise Security
  • Firewall Protection Supported: Threat Protection
  • Firewall Protection Supported: Secure IPsec VPN Connectivity
  • Firewall Protection Supported: TLS Decryption

A separate IOS XE and IOx issue

The same CSA alert also covers CVE-2020-3227, scored 9.8 by the CSA in 2020. It describes incorrect handling of authorization-token requests in Cisco IOS XE releases 16.3.1 and later when IOx application hosting infrastructure is configured. This is an IOS XE/IOx issue in that alert—not evidence that the industrial router models listed for CVE-2020-3205, CVE-2020-3198, and CVE-2020-3258 are affected by CVE-2020-3227. Verify the exact release and configuration conditions in Cisco’s advisory.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to identify exposure and plan remediation

The CSA advised administrators of affected products to install the latest security updates. Its alert does not provide the fixed-release matrix needed to identify a specific IOS or IOS XE version for every model. Do not infer a fixed version from a product-family name or from the advisory date; confirm the exact release in Cisco’s primary advisory for the relevant CVE and device.

  1. Inventory the device: Record its exact model, hardware revision, IOS or IOS XE release train and version, and relevant configuration. For CVE-2020-3227, determine whether IOx application hosting infrastructure is configured.
  2. Check each CVE independently: Use Cisco’s individual advisory to match the model, software release, and any feature or configuration conditions to the affected and fixed releases. Do not assume one family-level result applies to every CVE.
  3. Select the confirmed fixed release: Follow Cisco’s release guidance for that device and software train. The available 2020 reporting and CSA alert do not establish exact fixed versions.
  4. Schedule the change: Account for the maintenance window and operational impact of updating industrial network equipment. Follow the organization’s change-control and validation procedures.
  5. Verify after the update: Confirm the installed version and device operation against the change plan, then retain the result in the asset record.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the 2020 exploitation statement means now

SecurityWeek reported that Cisco had found no evidence of exploitation at the time of publication in June 2020. That statement describes Cisco’s awareness then; it is not a current assessment of exploitation activity and should not be used to decide whether to remediate now.

Quick Recap

Bestseller No. 1
Cisco 3000 Network Security/Firewall Appliance
Cisco 3000 Network Security/Firewall Appliance
2 X 10/100/1000 + 2 X GIGABIT SFP; CHASIS 64 GB MSATA; DC POWER; DIN RAIL MOUNTABLE; INDUSTRIAL SECURITY APPLIANCE
$3,600.00
Bestseller No. 2
Cisco Secure Firewall 1210 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN
Cisco Secure Firewall 1210 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN
Functionality: Centralized Management; Firewall Protection Supported: Enterprise Security; Firewall Protection Supported: Threat Protection
$2,813.38
Best Value
CISCO DESIGNED Meraki MX250 Network Security/Firewall - Appliance Only
  • Unified management for security, SD-WAN, Wi-Fi, switching, MDM, and IoT Centralized management via web-based dashboard or API True zero-touch provisioning Smartphone-like firmware updates
Rank #4
Meraki MX75-HW Security Appliance Bundle | Cloud-Managed Firewall | 1-Year Advanced Security License & Support Included | 1 Gbps Throughput | 3X WAN (1x SFP, 2X GbE) | SD-WAN & VPN
  • SECURITY & SD-WAN PERFORMANCE: Meraki MX75-HW cloud-managed appliance delivers up to 1 Gbps firewall throughput and 500 Mbps VPN throughput, supporting small branch deployments with up to 200 users.
  • ADVANCED THREAT PROTECTION: Integrated intrusion prevention, advanced malware protection, and content filtering safeguard your network against evolving cyber threats.
  • CLOUD-MANAGED SIMPLICITY: Zero-touch provisioning and centralized management via the Meraki Dashboard for seamless configuration, monitoring, and troubleshooting.
  • APPLICATION-AWARE CONTROL: Layer 7 traffic shaping prioritizes critical applications like voice and video while optimizing overall network performance.
  • BUILT-IN SD-WAN & VPN: Simplifies multi-site connectivity with intelligent path control, automatic failover, and secure site-to-site VPN.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.