← Back

CVE-2020-26073

Published: Nov 18, 2024Modified: Aug 4, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to application programmatic interfaces (APIs). An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and gain access to sensitive information including credentials or user tokens.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Affected (46)

1 product
Catalyst Sd Wan Manager
Configuration A
46 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 17.2.10
Version 17.2.4
Version 17.2.5
Version 17.2.6
Version 17.2.7
Version 17.2.8
Version 17.2.9
Version 18.2.0
Version 18.3.0
Version 18.3.1.1
Version 18.3.1
Version 18.3.3.1
Version 18.3.3
Version 18.3.4
Version 18.3.5
Version 18.3.6.1
Version 18.3.6
Version 18.3.7
Version 18.3.8
Version 18.4.0.1
Version 18.4.0
Version 18.4.1
Version 18.4.302
Version 18.4.303
Version 18.4.3
Version 18.4.4
Version 18.4.501_es
Version 18.4.5
Version 19.0.0
Version 19.0.1a
Version 19.1.0
Version 19.2.097
Version 19.2.098
Version 19.2.099
Version 19.2.0
Version 19.2.1
Version 19.2.2
Version 19.2.31
Version 19.2.3
Version 19.2.929
Version 19.3.0
Version 20.1.1.1
Version 20.1.12
Version 20.1.1
Version 20.1.2
Version 20.3.1

Timeline

No history available yet.