📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government and Defense CRITICAL 37m Global general Technology / Consumer Protection MEDIUM 48m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 37m Global general Technology / Consumer Protection MEDIUM 48m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 37m Global general Technology / Consumer Protection MEDIUM 48m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h
Vulnerabilities

CVE-2026-20104

Medium
A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Swit
CWE-124 — Weakness Type
Published: Mar 25, 2026  ·  Modified: Mar 28, 2026  ·  Source: NVD
CVSS v3
6.1
🔗 NVD Official
📄 Description (English)

A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute arbitrary code at boot time and break the chain of trust.

This vulnerability is due to insufficient validation of software at boot time. An attacker could exploit this vulnerability by manipulating the loaded binaries on an affected device to bypass some of the integrity checks that are performed during the boot process. A successful exploit could allow the attacker to execute code that bypasses the requirement to run Cisco-signed images.

Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates because this vulnerability allows an attacker to bypass a major security feature of a device.

🤖 AI Executive Summary

A critical bootloader vulnerability in Cisco Catalyst switches allows authenticated local attackers with level-15 privileges or unauthenticated attackers with physical access to execute arbitrary code and bypass the chain of trust. This vulnerability affects multiple Cisco switch models widely deployed in Saudi infrastructure, enabling attackers to run unsigned code and compromise device integrity at boot time. No patch is currently available, making this a significant risk for organizations relying on these devices for network security.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 24, 2026 05:36
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses severe risk to Saudi critical infrastructure sectors: (1) Banking & Financial Services (SAMA-regulated) — Catalyst switches are core network infrastructure for payment systems and inter-bank communications; (2) Government & Defense (NCA oversight) — widespread deployment in government networks and critical infrastructure; (3) Energy Sector (ARAMCO, SEC) — Catalyst switches used in SCADA/ICS networks for oil and gas operations; (4) Telecommunications (STC, Mobily, Zain) — backbone network infrastructure; (5) Healthcare — hospital network infrastructure for patient data protection. The ability to bypass code signing and execute arbitrary code at boot time enables persistent compromise, rootkit installation, and complete device takeover, making this particularly dangerous for organizations managing sensitive national infrastructure.
🏢 Affected Saudi Sectors
Banking & Financial Services Government & Defense Energy & Oil/Gas Telecommunications Healthcare Critical Infrastructure Transportation
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Inventory all affected Cisco Catalyst switch models (9200, ESS9300, IE9310, IE9320, IE3500, IE3505) in your environment
2. Restrict physical access to affected devices — implement badge access controls and surveillance
3. Disable remote management protocols (SSH, HTTPS) if not critical; use out-of-band management only
4. Implement strict access controls limiting level-15 privilege accounts to essential personnel only
5. Enable console port security and disable auxiliary ports

COMPENSATING CONTROLS (until patch available):
6. Deploy network segmentation — isolate affected switches from untrusted networks
7. Implement 802.1X authentication on all switch access ports
8. Monitor boot logs and system logs for unauthorized code execution attempts
9. Use SNMP read-only community strings; disable SNMP write access
10. Implement configuration change monitoring and alerting

DETECTION RULES:
11. Monitor for: (a) Unexpected bootloader modifications via syslog analysis; (b) Failed integrity check messages during boot; (c) Unauthorized privilege escalation attempts; (d) Unexpected code execution during boot phase
12. Establish baseline of boot checksums and monitor for deviations
13. Alert on any physical tampering indicators or console access logs
14. Monitor for unsigned image loading attempts in system logs

PATCHING STRATEGY:
15. Subscribe to Cisco security advisories for patch availability
16. Plan for device replacement or firmware updates immediately upon patch release
17. Maintain offline backup of legitimate Cisco-signed images
18. Test patches in isolated lab environment before production deployment
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بحصر جميع نماذج مفاتيح Cisco Catalyst المتأثرة (9200، ESS9300، IE9310، IE9320، IE3500، IE3505) في بيئتك
2. قيّد الوصول الفيزيائي إلى الأجهزة المتأثرة — طبّق عناصر تحكم الوصول بالبطاقة والمراقبة
3. عطّل بروتوكولات الإدارة البعيدة (SSH، HTTPS) إذا لم تكن حرجة؛ استخدم الإدارة خارج النطاق فقط
4. طبّق عناصر تحكم وصول صارمة تقصر حسابات امتياز المستوى 15 على الموظفين الأساسيين فقط
5. فعّل أمان منفذ وحدة التحكم وعطّل المنافذ الإضافية

عناصر التحكم التعويضية (حتى توفر التصحيح):
6. طبّق تقسيم الشبكة — عزل المفاتيح المتأثرة عن الشبكات غير الموثوقة
7. طبّق مصادقة 802.1X على جميع منافذ الوصول للمفتاح
8. راقب سجلات الإقلاع وسجلات النظام لمحاولات تنفيذ أكواد غير مصرح بها
9. استخدم سلاسل مجتمع SNMP للقراءة فقط؛ عطّل وصول كتابة SNMP
10. طبّق مراقبة التغييرات في الإعدادات والتنبيهات

قواعد الكشف:
11. راقب: (أ) تعديلات محمل الإقلاع غير المتوقعة عبر تحليل syslog؛ (ب) رسائل فحص السلامة الفاشلة أثناء الإقلاع؛ (ج) محاولات تصعيد الامتيازات غير المصرح بها؛ (د) تنفيذ أكواد غير متوقع أثناء مرحلة الإقلاع
12. أنشئ خط أساس لمجاميع التحقق من الإقلاع وراقب الانحرافات
13. نبّه على أي مؤشرات عبث فيزيائي أو سجلات وصول وحدة التحكم
14. راقب محاولات تحميل الصور غير الموقعة في سجلات النظام
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.8.1 — Asset Management and Inventory Control ECC 2024 A.8.2 — Information Security Perimeter ECC 2024 A.8.3 — Physical and Environmental Security ECC 2024 A.12.2 — Cryptography and Code Integrity ECC 2024 A.12.6 — Management of Technical Vulnerabilities
🔵 SAMA CSF
SAMA CSF ID.AM-1 — Asset Management SAMA CSF PR.AC-1 — Access Control SAMA CSF PR.DS-6 — Data Integrity SAMA CSF DE.CM-1 — Detection and Analysis SAMA CSF RS.MI-1 — Incident Response and Recovery
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 — Access Control ISO 27001:2022 A.8.1 — Asset Management ISO 27001:2022 A.8.2 — Information Security Perimeter ISO 27001:2022 A.8.3 — Physical and Environmental Security ISO 27001:2022 A.8.32 — Change Management
🟣 PCI DSS v4.0.1
PCI DSS 1.1 — Firewall Configuration Standards PCI DSS 2.1 — Default Passwords and Security Parameters PCI DSS 6.2 — Security Patches and Updates PCI DSS 8.1 — User Access Control
📊 CVSS Score
6.1
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack VectorP — Physical
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.1
CWECWE-124
Exploit No
Patch ✗ No
Published 2026-03-25
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-124
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.