4.3
CVE-2026-20189
- EPSS 0.04%
- Veröffentlicht 06.05.2026 16:15:24
- Zuletzt bearbeitet 06.05.2026 18:59:53
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
Cisco Prime Infrastructure Information Disclosure Vulnerability
A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL request to an affected device. A successful exploit could allow the attacker to download sensitive log files that they would otherwise not have authorization to access. To exploit this vulnerability, the attacker must have valid credentials to access the web-based management interface of the affected device.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCisco
≫
Produkt
Cisco Prime Infrastructure
Default Statusunknown
Version
3.6.0
Status
affected
Version
3.7.0
Status
affected
Version
3.4.0
Status
affected
Version
3.3.0
Status
affected
Version
3.5.0
Status
affected
Version
3.2.0-FIPS
Status
affected
Version
3.8.0-FED
Status
affected
Version
3.9.0
Status
affected
Version
3.8.0
Status
affected
Version
3.10.0
Status
affected
Version
3.9.1
Status
affected
Version
3.8.1
Status
affected
Version
3.7.1
Status
affected
Version
3.5.1
Status
affected
Version
3.4.2
Status
affected
Version
3.3.1
Status
affected
Version
3.2.1
Status
affected
Version
3.2.2
Status
affected
Version
3.4.1
Status
affected
Version
3.10.2
Status
affected
Version
3.10.3
Status
affected
Version
3.10
Status
affected
Version
3.10.1
Status
affected
Version
3.7.1 Update 03
Status
affected
Version
3.7.1 Update 04
Status
affected
Version
3.7.1 Update 06
Status
affected
Version
3.7.1 Update 07
Status
affected
Version
3.8.1 Update 01
Status
affected
Version
3.8.1 Update 02
Status
affected
Version
3.8.1 Update 03
Status
affected
Version
3.8.1 Update 04
Status
affected
Version
3.9.1 Update 01
Status
affected
Version
3.9.1 Update 02
Status
affected
Version
3.9.1 Update 03
Status
affected
Version
3.9.1 Update 04
Status
affected
Version
3.10 Update 01
Status
affected
Version
3.4.2 Update 01
Status
affected
Version
3.6.0 Update 04
Status
affected
Version
3.6.0 Update 02
Status
affected
Version
3.6.0 Update 03
Status
affected
Version
3.6.0 Update 01
Status
affected
Version
3.5.1 Update 03
Status
affected
Version
3.5.1 Update 01
Status
affected
Version
3.5.1 Update 02
Status
affected
Version
3.7.0 Update 03
Status
affected
Version
3.8.0 Update 01
Status
affected
Version
3.8.0 Update 02
Status
affected
Version
3.7.1 Update 01
Status
affected
Version
3.7.1 Update 02
Status
affected
Version
3.7.1 Update 05
Status
affected
Version
3.9.0 Update 01
Status
affected
Version
3.3.0 Update 01
Status
affected
Version
3.4.1 Update 02
Status
affected
Version
3.4.1 Update 01
Status
affected
Version
3.5.0 Update 03
Status
affected
Version
3.5.0 Update 01
Status
affected
Version
3.5.0 Update 02
Status
affected
Version
3.10.4
Status
affected
Version
3.10.4 Update 01
Status
affected
Version
3.10.4 Update 02
Status
affected
Version
3.10.4 Update 03
Status
affected
Version
3.10.5
Status
affected
Version
3.10.6
Status
affected
Version
3.10.6 Update 01
Status
affected
Version
3.10.6 Update 02
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.117 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@cisco.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.