CVE-2020-26072

HIGH

Cisco IoT Field Network Director < 4.6.1 - Authenticated Improper Access Control via SOAP API

Title source: llm
STIX 2.1

Description

A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An attacker could exploit this vulnerability by sending SOAP API requests to affected devices for devices that are outside their authorized domain. A successful exploit could allow the attacker to access and modify information on devices that belong to a different domain.

References (1)

Core 1
Core References

Scores

CVSS v3 8.7
EPSS 0.0023
EPSS Percentile 45.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284 CWE-269
Status published
Products (1)
cisco/iot_field_network_director < 4.6.1
Published Nov 18, 2020
Tracked Since Feb 18, 2026