CVE-2020-27125

HIGH

Cisco Security Manager - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by viewing source code. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

References (1)

Core 1
Core References

Scores

CVSS v3 7.4
EPSS 0.0111
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
cisco/security_manager < 4.21
Published Nov 17, 2020
Tracked Since Feb 18, 2026