CVE-2020-27130 is a critical directory traversal vulnerability in Cisco Security Manager that allows an unauthenticated, remote attacker to download arbitrary sensitive files. With a CVSS score of 9.1, this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to high confidentiality and integrity impacts. While there is no known public exploit code or active exploitation listed in KEV, the vulnerability has garnered significant community attention with two media articles and two community discussions, indicating awareness among threat actors. Organizations using Cisco Security Manager should prioritize patching to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.21CPE matchmatch criteria | cpe:2.3:a:cisco:security_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.