4.3

CVE-2026-20189

Medienbericht

Cisco Prime Infrastructure Information Disclosure Vulnerability

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server.

This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL request to an affected device. A successful exploit could allow the attacker to download sensitive log files that they would otherwise not have authorization to access.
To exploit this vulnerability, the attacker must have valid credentials to access the web-based management interface of the affected device.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCisco
Produkt Cisco Prime Infrastructure
Default Statusunknown
Version 3.6.0
Status affected
Version 3.7.0
Status affected
Version 3.4.0
Status affected
Version 3.3.0
Status affected
Version 3.5.0
Status affected
Version 3.2.0-FIPS
Status affected
Version 3.8.0-FED
Status affected
Version 3.9.0
Status affected
Version 3.8.0
Status affected
Version 3.10.0
Status affected
Version 3.9.1
Status affected
Version 3.8.1
Status affected
Version 3.7.1
Status affected
Version 3.5.1
Status affected
Version 3.4.2
Status affected
Version 3.3.1
Status affected
Version 3.2.1
Status affected
Version 3.2.2
Status affected
Version 3.4.1
Status affected
Version 3.10.2
Status affected
Version 3.10.3
Status affected
Version 3.10
Status affected
Version 3.10.1
Status affected
Version 3.7.1 Update 03
Status affected
Version 3.7.1 Update 04
Status affected
Version 3.7.1 Update 06
Status affected
Version 3.7.1 Update 07
Status affected
Version 3.8.1 Update 01
Status affected
Version 3.8.1 Update 02
Status affected
Version 3.8.1 Update 03
Status affected
Version 3.8.1 Update 04
Status affected
Version 3.9.1 Update 01
Status affected
Version 3.9.1 Update 02
Status affected
Version 3.9.1 Update 03
Status affected
Version 3.9.1 Update 04
Status affected
Version 3.10 Update 01
Status affected
Version 3.4.2 Update 01
Status affected
Version 3.6.0 Update 04
Status affected
Version 3.6.0 Update 02
Status affected
Version 3.6.0 Update 03
Status affected
Version 3.6.0 Update 01
Status affected
Version 3.5.1 Update 03
Status affected
Version 3.5.1 Update 01
Status affected
Version 3.5.1 Update 02
Status affected
Version 3.7.0 Update 03
Status affected
Version 3.8.0 Update 01
Status affected
Version 3.8.0 Update 02
Status affected
Version 3.7.1 Update 01
Status affected
Version 3.7.1 Update 02
Status affected
Version 3.7.1 Update 05
Status affected
Version 3.9.0 Update 01
Status affected
Version 3.3.0 Update 01
Status affected
Version 3.4.1 Update 02
Status affected
Version 3.4.1 Update 01
Status affected
Version 3.5.0 Update 03
Status affected
Version 3.5.0 Update 01
Status affected
Version 3.5.0 Update 02
Status affected
Version 3.10.4
Status affected
Version 3.10.4 Update 01
Status affected
Version 3.10.4 Update 02
Status affected
Version 3.10.4 Update 03
Status affected
Version 3.10.5
Status affected
Version 3.10.6
Status affected
Version 3.10.6 Update 01
Status affected
Version 3.10.6 Update 02
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.117
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@cisco.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.