cbcvebase.
CVE-2020-26078
published 2020-11-18

CVE-2020-26078: A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected…

medium6.5CVSS 3.1
AVNACLPRHUINSUCNIHAH
A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected system. The vulnerability is due to insufficient file system protections. An attacker could exploit this vulnerability by crafting API requests and sending them to an affected system. A successful exploit could allow the attacker to overwrite files on an affected system.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_iot_field_network_director
ciscoiot_field_network_director< 4.6.14.6.1
ciscoiot_field_network_director_file_overwrite