7.5
CVE-2026-20133
- EPSS 0.06%
- Veröffentlicht 25.02.2026 16:13:56
- Zuletzt bearbeitet 04.03.2026 21:20:11
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Catalyst Sd-wan Manager Version < 20.9.8.2
Cisco ≫ Catalyst Sd-wan Manager Version >= 20.11 < 20.12.5.3
Cisco ≫ Catalyst Sd-wan Manager Version >= 20.13 < 20.15.4.2
Cisco ≫ Catalyst Sd-wan Manager Version >= 20.16 < 20.18.2.1
Cisco ≫ Catalyst Sd-wan Manager Version20.12.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.198 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| psirt@cisco.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.