S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-26073 Scanner

CVE-2020-26073 scanner - Directory Traversal vulnerability in Cisco SD-WAN vManage Software

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
7
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-26073
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to application programmatic interfaces (APIs). An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and gain access to sensitive information including credentials or user tokens.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Cisco Catalyst SD-WAN Managerby Cisco
20.1.12
catalyst_sd-wan_managerby cisco
20.1.12
Updated Aug 21, 2026View on NVD →
Detail

Cisco SD-WAN vManage Software is a crucial component of the Cisco SD-WAN solution. This software is used for centralized management of an SD-WAN network. It provides a GUI-based management platform that can be used to configure, monitor, and troubleshoot the SD-WAN devices in the network. With Cisco SD-WAN vManage Software, network operators can manage multiple SD-WAN deployments with ease, and ensure that policies and configurations are consistent across the network. Additionally, vManage Software provides real-time visibility and analytics of the SD-WAN network, enabling network operators to identify and address issues quickly.

One of the vulnerabilities detected in Cisco SD-WAN vManage Software is CVE-2020-26073. This vulnerability is a Directory Traversal vulnerability that affects v. <20.3.2. Directory Traversal is a technique used to exploit web server vulnerabilities by accessing files and directories outside of the web root directory. In the case of CVE-2020-26073, an attacker could use this vulnerability to access sensitive information or execute unauthorized code on the vManage Software.

Exploiting CVE-2020-26073 can lead to serious consequences for organizations with SD-WAN deployments. If sensitive information is accessed or unauthorized code is executed, network configurations can be modified, allowing attackers to gain access to critical resources within the network. This can ultimately lead to data loss, service disruptions, and reputational damage.

By utilizing the pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets. With comprehensive vulnerability scanning, proactive risk monitoring, and expert guidance, s4e.io helps organizations identify and address vulnerabilities before they can be exploited. Don't wait until it's too late – protect your digital assets with s4e.io today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations can take the following precautions:

  • Apply the latest software updates provided by Cisco as soon as possible.
  • Restrict access to the vManage interface only to trusted IP addresses.
  • Implement strong password policies for vManage user accounts.
  • Monitor vManage logs for unauthorized access attempts.
  • Use a web application firewall to prevent exploitation of directory traversal vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-26073 scanner - Directory Traversal vulnerability in Cisco SD-WAN vManage Software S4E