Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-20155

Опубликовано: 01 апр. 2026
Источник: nvd
CVSS3: 8
EPSS Низкий

Описание

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access.

This vulnerability is due to improper authorization checks on a REST API endpoint of an affected device. An attacker could exploit this vulnerability by querying the affected endpoint. A successful exploit could allow the attacker to view session information of active Cisco EPNM users, including users with administrative privileges, which could result in the affected device being compromised.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*
Версия до 8.1.2 (исключая)

EPSS

Процентиль: 19%
0.0027
Низкий

8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8
github
4 месяца назад

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnerability is due to improper authorization checks on a REST API endpoint of an affected device. An attacker could exploit this vulnerability by querying the affected endpoint. A successful exploit could allow the attacker to view session information of active Cisco EPNM users, including users with administrative privileges, which could result in the affected device being compromised.

CVSS3: 8
fstec
5 месяцев назад

Уязвимость веб-интерфейса управления программного средства управления сетевыми сервисами Cisco Evolved Programmable Network Manager (EPNM), позволяющая нарушителю скомпрометировать уязвимое устройство

EPSS

Процентиль: 19%
0.0027
Низкий

8 High

CVSS3

Дефекты

CWE-862