7.5
CVE-2020-26073
- EPSS 89.72%
- Veröffentlicht 18.11.2024 16:15:05
- Zuletzt bearbeitet 04.08.2025 14:30:40
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to application programmatic interfaces (APIs). An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and gain access to sensitive information including credentials or user tokens.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Catalyst Sd-wan Manager Version17.2.4
Cisco ≫ Catalyst Sd-wan Manager Version17.2.5
Cisco ≫ Catalyst Sd-wan Manager Version17.2.6
Cisco ≫ Catalyst Sd-wan Manager Version17.2.7
Cisco ≫ Catalyst Sd-wan Manager Version17.2.8
Cisco ≫ Catalyst Sd-wan Manager Version17.2.9
Cisco ≫ Catalyst Sd-wan Manager Version17.2.10
Cisco ≫ Catalyst Sd-wan Manager Version18.2.0
Cisco ≫ Catalyst Sd-wan Manager Version18.3.0
Cisco ≫ Catalyst Sd-wan Manager Version18.3.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.1.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.3
Cisco ≫ Catalyst Sd-wan Manager Version18.3.3.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.4
Cisco ≫ Catalyst Sd-wan Manager Version18.3.5
Cisco ≫ Catalyst Sd-wan Manager Version18.3.6
Cisco ≫ Catalyst Sd-wan Manager Version18.3.6.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.7
Cisco ≫ Catalyst Sd-wan Manager Version18.3.8
Cisco ≫ Catalyst Sd-wan Manager Version18.4.0
Cisco ≫ Catalyst Sd-wan Manager Version18.4.0.1
Cisco ≫ Catalyst Sd-wan Manager Version18.4.1
Cisco ≫ Catalyst Sd-wan Manager Version18.4.3
Cisco ≫ Catalyst Sd-wan Manager Version18.4.4
Cisco ≫ Catalyst Sd-wan Manager Version18.4.5
Cisco ≫ Catalyst Sd-wan Manager Version18.4.302
Cisco ≫ Catalyst Sd-wan Manager Version18.4.303
Cisco ≫ Catalyst Sd-wan Manager Version18.4.501_es
Cisco ≫ Catalyst Sd-wan Manager Version19.0.0
Cisco ≫ Catalyst Sd-wan Manager Version19.0.1a
Cisco ≫ Catalyst Sd-wan Manager Version19.1.0
Cisco ≫ Catalyst Sd-wan Manager Version19.2.0
Cisco ≫ Catalyst Sd-wan Manager Version19.2.1
Cisco ≫ Catalyst Sd-wan Manager Version19.2.2
Cisco ≫ Catalyst Sd-wan Manager Version19.2.3
Cisco ≫ Catalyst Sd-wan Manager Version19.2.31
Cisco ≫ Catalyst Sd-wan Manager Version19.2.097
Cisco ≫ Catalyst Sd-wan Manager Version19.2.098
Cisco ≫ Catalyst Sd-wan Manager Version19.2.099
Cisco ≫ Catalyst Sd-wan Manager Version19.2.929
Cisco ≫ Catalyst Sd-wan Manager Version19.3.0
Cisco ≫ Catalyst Sd-wan Manager Version20.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.1.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.1.2
Cisco ≫ Catalyst Sd-wan Manager Version20.1.12
Cisco ≫ Catalyst Sd-wan Manager Version20.3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 89.72% | 0.995 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
psirt@cisco.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-35 Path Traversal: '.../...//'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.