← Vulnerability feed

Vulnerability record · CVE-2020-3455 · published 21 October 2020

CVE-2020-3455: Cisco firepower extensible operating system vulnerability

Cisco · Firepower Extensible Operating System

A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass the secure boot mechanisms. The vulnerability is due to insufficient protections of the secure boot process. An attacker could exploit this vulnerability by injecting code into a specific file that is then referenced during the device boot process. A successful exploit could allow the attacker to break the chain of trust and inject code into the boot process of the device which would be executed at each boot and maintain persistence across reboots.

7.8 CVSS 3.1 High EPSS 0.35% · top 74.1% CWE-693 · CWE-693
7.8CVSS 3.1 base score, v2 7.2
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass the secure boot mechanisms. The vulnerability is due to insufficient protections of the secure boot process. An attacker could exploit this vulnerability by injecting code into a specific file that is then referenced during the device boot process. A successful exploit could allow the attacker to break the chain of trust and inject code into the boot process of the device which would be executed at each boot and maintain persistence across reboots.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3455 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0310Cisco nx-os out-of-bounds read vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 4.1%9.8CVE-2015-6435Cisco firepower extensible operating system os command injection vulnerabilityAn unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(…EPSS 8.7%8.8CVE-2021-1368Cisco nx-os out-of-bounds write vulnerabilityA vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, a…EPSS 0.46%8.8CVE-2020-3456Cisco firepower extensible operating system cross-site request forgery vulnerabilityA vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cros…EPSS 0.56%8.8CVE-2020-3172Cisco firepower extensible operating system improper input validation vulnerabilityA vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent atta…EPSS 1.9%8.8CVE-2018-0303Cisco nx-os improper input validation vulnerabilityA vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent at…EPSS 1.1%8.8CVE-2017-12277Cisco firepower extensible operating system improper input validation vulnerabilityA vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security…EPSS 3.8%8.6CVE-2020-3517Cisco firepower extensible operating system null pointer dereference vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cau…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2020-3455), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.