CVE-2026-20128
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-257
Almacenamiento de contraseñas en formato recuperable
Fecha de publicación:
25/02/2026
Última modificación:
25/02/2026
Descripción
*** Pendiente de traducción *** A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system. To exploit this vulnerability, the attacker must have valid&nbsp;vmanage credentials on the affected system.<br />
<br />
This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by accessing the filesystem as a low-privileged user and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges.<br />
Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA



