CVE-2020-26065: Path Traversal
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-26065?
CVE-2020-26065 is a vulnerability in the web-based management interface of Cisco SD-WAN vManage Software that could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system.
What is the severity of CVE-2020-26065?
The severity of CVE-2020-26065 is medium with a CVSS score of 6.5.
How does CVE-2020-26065 affect Cisco Catalyst SD-WAN Manager?
CVE-2020-26065 affects Cisco Catalyst SD-WAN Manager versions 17.2.4 to 20.3.1.
What is the Common Weakness Enumeration (CWE) for CVE-2020-26065?
The Common Weakness Enumeration (CWE) for CVE-2020-26065 is CWE-22.
How can I fix CVE-2020-26065?
To fix CVE-2020-26065, it is recommended to upgrade to a fixed version of Cisco Catalyst SD-WAN Manager software.