PT-2026-3788 · Cisco · Cisco Intersight Virtual Appliance
Published
2026-01-21
·
Updated
2026-01-22
·
CVE-2026-20092
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Intersight Virtual Appliance (affected versions not specified)
Description
A flaw exists in the read-only maintenance shell of the appliance that may allow a local attacker with administrative privileges to gain root access. This is caused by incorrect file permissions on configuration files for system accounts within the maintenance shell. An attacker could exploit this by accessing the maintenance shell as a read-only administrator and altering system files to obtain root privileges. A successful exploit could grant the attacker complete control of the appliance, potentially allowing access to sensitive data, modification of workloads and configurations, and a denial of service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Intersight Virtual Appliance