Back to CVE List

CVE-2026-20168

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Vulnerability Description

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access.

This vulnerability is due to insufficient file access checks. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to read files that they are not authorized to access.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-388
Source
NVD
Vendor
Cisco
Product
Cisco IoT Field Network Director (IoT-FND)

External References

Discussion (0)

Add Comment

No comments yet. Be the first!