.. / CVE-2020-26073

Exploit for Cisco SD-WAN vManage Software - Local File Inclusion (CVE-2020-26073)

Description:

Cisco SD-WAN vManage Software in the application data endpoints is vulnerable to local file inclusion which could allow an unauthenticated, remote attacker to gain access to sensitive information.

Nuclei Template

View the template here CVE-2020-26073.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-26073.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-26073
https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-vman-traversal-hQh24tmk.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26073