7.8
CVE-2020-26074
- EPSS 0.05%
- Published 18.11.2024 16:15:06
- Last modified 04.08.2025 14:31:19
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating system. The vulnerability is due to improper validation of path input to the system file transfer functions. An attacker could exploit this vulnerability by sending requests that contain specially crafted path variables to the vulnerable system. A successful exploit could allow the attacker to overwrite arbitrary files, allowing the attacker to modify the system in such a way that could allow the attacker to gain escalated privileges.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Catalyst Sd-wan Manager Version17.2.4
Cisco ≫ Catalyst Sd-wan Manager Version17.2.5
Cisco ≫ Catalyst Sd-wan Manager Version17.2.6
Cisco ≫ Catalyst Sd-wan Manager Version17.2.7
Cisco ≫ Catalyst Sd-wan Manager Version17.2.8
Cisco ≫ Catalyst Sd-wan Manager Version17.2.9
Cisco ≫ Catalyst Sd-wan Manager Version17.2.10
Cisco ≫ Catalyst Sd-wan Manager Version18.2.0
Cisco ≫ Catalyst Sd-wan Manager Version18.3.0
Cisco ≫ Catalyst Sd-wan Manager Version18.3.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.1.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.3
Cisco ≫ Catalyst Sd-wan Manager Version18.3.3.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.4
Cisco ≫ Catalyst Sd-wan Manager Version18.3.5
Cisco ≫ Catalyst Sd-wan Manager Version18.3.6
Cisco ≫ Catalyst Sd-wan Manager Version18.3.6.1
Cisco ≫ Catalyst Sd-wan Manager Version18.3.7
Cisco ≫ Catalyst Sd-wan Manager Version18.3.8
Cisco ≫ Catalyst Sd-wan Manager Version18.4.0
Cisco ≫ Catalyst Sd-wan Manager Version18.4.0.1
Cisco ≫ Catalyst Sd-wan Manager Version18.4.1
Cisco ≫ Catalyst Sd-wan Manager Version18.4.3
Cisco ≫ Catalyst Sd-wan Manager Version18.4.4
Cisco ≫ Catalyst Sd-wan Manager Version18.4.5
Cisco ≫ Catalyst Sd-wan Manager Version18.4.302
Cisco ≫ Catalyst Sd-wan Manager Version18.4.303
Cisco ≫ Catalyst Sd-wan Manager Version18.4.501_es
Cisco ≫ Catalyst Sd-wan Manager Version19.0.0
Cisco ≫ Catalyst Sd-wan Manager Version19.0.1a
Cisco ≫ Catalyst Sd-wan Manager Version19.1.0
Cisco ≫ Catalyst Sd-wan Manager Version19.2.0
Cisco ≫ Catalyst Sd-wan Manager Version19.2.1
Cisco ≫ Catalyst Sd-wan Manager Version19.2.2
Cisco ≫ Catalyst Sd-wan Manager Version19.2.3
Cisco ≫ Catalyst Sd-wan Manager Version19.2.31
Cisco ≫ Catalyst Sd-wan Manager Version19.2.097
Cisco ≫ Catalyst Sd-wan Manager Version19.2.098
Cisco ≫ Catalyst Sd-wan Manager Version19.2.099
Cisco ≫ Catalyst Sd-wan Manager Version19.2.929
Cisco ≫ Catalyst Sd-wan Manager Version19.3.0
Cisco ≫ Catalyst Sd-wan Manager Version20.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.1.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.1.2
Cisco ≫ Catalyst Sd-wan Manager Version20.1.12
Cisco ≫ Catalyst Sd-wan Manager Version20.3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.155 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@cisco.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.