CVE-2020-27125 is a critical vulnerability in Cisco Security Manager that allows an unauthenticated, remote attacker to access sensitive information due to insufficient protection of static credentials. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, public exploits have been reported, and the vulnerability has garnered significant community discussion and media coverage, indicating active awareness and potential for exploitation. There are currently no known Metasploit, Nuclei, or ExploitDB modules available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.21CPE matchmatch criteria | cpe:2.3:a:cisco:security_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.