CVE Vulnerabilities

CVE-2020-26074

Execution with Unnecessary Privileges

Published: Nov 18, 2024 | Modified: Aug 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating system. The vulnerability is due to improper validation of path input to the system file transfer functions. An attacker could exploit this vulnerability by sending requests that contain specially crafted path variables to the vulnerable system. A successful exploit could allow the attacker to overwrite arbitrary files, allowing the attacker to modify the system in such a way that could allow the attacker to gain escalated privileges.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Weakness

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Affected Software

Name Vendor Start Version End Version
Catalyst_sd-wan_manager Cisco 17.2.4 (including) 17.2.4 (including)
Catalyst_sd-wan_manager Cisco 17.2.5 (including) 17.2.5 (including)
Catalyst_sd-wan_manager Cisco 17.2.6 (including) 17.2.6 (including)
Catalyst_sd-wan_manager Cisco 17.2.7 (including) 17.2.7 (including)
Catalyst_sd-wan_manager Cisco 17.2.8 (including) 17.2.8 (including)
Catalyst_sd-wan_manager Cisco 17.2.9 (including) 17.2.9 (including)
Catalyst_sd-wan_manager Cisco 17.2.10 (including) 17.2.10 (including)
Catalyst_sd-wan_manager Cisco 18.2.0 (including) 18.2.0 (including)
Catalyst_sd-wan_manager Cisco 18.3.0 (including) 18.3.0 (including)
Catalyst_sd-wan_manager Cisco 18.3.1 (including) 18.3.1 (including)
Catalyst_sd-wan_manager Cisco 18.3.1.1 (including) 18.3.1.1 (including)
Catalyst_sd-wan_manager Cisco 18.3.3 (including) 18.3.3 (including)
Catalyst_sd-wan_manager Cisco 18.3.3.1 (including) 18.3.3.1 (including)
Catalyst_sd-wan_manager Cisco 18.3.4 (including) 18.3.4 (including)
Catalyst_sd-wan_manager Cisco 18.3.5 (including) 18.3.5 (including)
Catalyst_sd-wan_manager Cisco 18.3.6 (including) 18.3.6 (including)
Catalyst_sd-wan_manager Cisco 18.3.6.1 (including) 18.3.6.1 (including)
Catalyst_sd-wan_manager Cisco 18.3.7 (including) 18.3.7 (including)
Catalyst_sd-wan_manager Cisco 18.3.8 (including) 18.3.8 (including)
Catalyst_sd-wan_manager Cisco 18.4.0 (including) 18.4.0 (including)
Catalyst_sd-wan_manager Cisco 18.4.0.1 (including) 18.4.0.1 (including)
Catalyst_sd-wan_manager Cisco 18.4.1 (including) 18.4.1 (including)
Catalyst_sd-wan_manager Cisco 18.4.3 (including) 18.4.3 (including)
Catalyst_sd-wan_manager Cisco 18.4.4 (including) 18.4.4 (including)
Catalyst_sd-wan_manager Cisco 18.4.5 (including) 18.4.5 (including)
Catalyst_sd-wan_manager Cisco 18.4.302 (including) 18.4.302 (including)
Catalyst_sd-wan_manager Cisco 18.4.303 (including) 18.4.303 (including)
Catalyst_sd-wan_manager Cisco 18.4.501_es (including) 18.4.501_es (including)
Catalyst_sd-wan_manager Cisco 19.0.0 (including) 19.0.0 (including)
Catalyst_sd-wan_manager Cisco 19.0.1a (including) 19.0.1a (including)
Catalyst_sd-wan_manager Cisco 19.1.0 (including) 19.1.0 (including)
Catalyst_sd-wan_manager Cisco 19.2.0 (including) 19.2.0 (including)
Catalyst_sd-wan_manager Cisco 19.2.1 (including) 19.2.1 (including)
Catalyst_sd-wan_manager Cisco 19.2.2 (including) 19.2.2 (including)
Catalyst_sd-wan_manager Cisco 19.2.3 (including) 19.2.3 (including)
Catalyst_sd-wan_manager Cisco 19.2.31 (including) 19.2.31 (including)
Catalyst_sd-wan_manager Cisco 19.2.097 (including) 19.2.097 (including)
Catalyst_sd-wan_manager Cisco 19.2.098 (including) 19.2.098 (including)
Catalyst_sd-wan_manager Cisco 19.2.099 (including) 19.2.099 (including)
Catalyst_sd-wan_manager Cisco 19.2.929 (including) 19.2.929 (including)
Catalyst_sd-wan_manager Cisco 19.3.0 (including) 19.3.0 (including)
Catalyst_sd-wan_manager Cisco 20.1.1 (including) 20.1.1 (including)
Catalyst_sd-wan_manager Cisco 20.1.1.1 (including) 20.1.1.1 (including)
Catalyst_sd-wan_manager Cisco 20.1.2 (including) 20.1.2 (including)
Catalyst_sd-wan_manager Cisco 20.1.12 (including) 20.1.12 (including)
Catalyst_sd-wan_manager Cisco 20.3.1 (including) 20.3.1 (including)

Potential Mitigations

References