PT-2026-3788 · Cisco · Cisco Intersight Virtual Appliance

CVE-2026-20092

·

Publicado

2026-01-21

·

Atualizado

2026-01-22

CVSS v2.0

6.2

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Intersight Virtual Appliance (affected versions not specified)
Description A flaw exists in the read-only maintenance shell of the appliance that may allow a local attacker with administrative privileges to gain root access. This is caused by incorrect file permissions on configuration files for system accounts within the maintenance shell. An attacker could exploit this by accessing the maintenance shell as a read-only administrator and altering system files to obtain root privileges. A successful exploit could grant the attacker complete control of the appliance, potentially allowing access to sensitive data, modification of workloads and configurations, and a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-01761
CVE-2026-20092

Produtos afetados

Cisco Intersight Virtual Appliance