CVE-2026-20168

MEDIUM

Cisco IoT Field Network Director Path Traversal Vulnerability

Title source: cna
STIX 2.1

Description

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to read files that they are not authorized to access.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-388
Status published
Products (30)
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.1.0
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.1.1
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.1.2
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.1.3
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.10.0
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.11.0
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.12.0
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.12.1
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.2.0
Cisco/Cisco IoT Field Network Director (IoT-FND) 4.3.0
... and 20 more
Published May 06, 2026
Tracked Since May 06, 2026