CVE-2026-20028: Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability
A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20028?
CVE-2026-20028 has a medium severity rating of 5.
How do I fix CVE-2026-20028?
To remediate CVE-2026-20028, apply the latest patches provided by Cisco for the Terminal Services Agent.
Who is affected by CVE-2026-20028?
Authenticated users of the Cisco Terminal Services Agent may be affected by CVE-2026-20028.
What does CVE-2026-20028 allow an attacker to do?
CVE-2026-20028 allows an authenticated remote attacker to bypass firewall rules associated with their account.
What is the impact of CVE-2026-20028?
The impact of CVE-2026-20028 includes unauthorized access to network services due to incorrect mapping of network connections.