Path traversal in Cisco Security Manager - CVE-2020-27130

 

Path traversal in Cisco Security Manager - CVE-2020-27130

Published: November 17, 2020 / Updated: November 17, 2020


Vulnerability identifier: #VU48456
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27130
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and download arbitrary files from the system.

Successful exploitation of this vulnerability can lead to full system compromise.


Affected software

Cisco Security Manager

How to mitigate CVE-2020-27130

Install update from vendor's website.

Cisco Security Manager - update to 4.22

External References

Related Security Bulletins