VDB
CVE-2020-27128
CVE-2020-27128
PUBLISHED
CVSS 6.5 MEDIUM
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to an arbitrary location on the targeted system.
EPSS 2.36% · 85.2th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
2.36%
85.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco SD-WAN vManage | n/a |
| cisco | sd-wan | 0 |
Exploit Intelligence
- 20201104 Cisco SD-WAN vManage Software Arbitrary File Creation Vulnerability (circl)
- ET EXPLOIT Cisco Viptela vManage Directory Traversal (CVE-2020-27128) (emergingthreats)
- ET EXPLOIT Cisco Viptela vManage Directory Traversal (CVE-2020-27128) (emergingthreats)
- ET EXPLOIT Cisco Viptela vManage Directory Traversal (CVE-2020-27128) (emergingthreats)
Timeline
- Nov 6, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 8, 2022 PoC Published
- Feb 28, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score