CVE detail
CVE-2020-27130
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to download arbitrary files from the affected device.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
- Cisco fixes exploitable RCEs in Cisco Security ManagerSecurity Affairs
Cisco released security updates to fix multiple pre-authentication RCE flaws with public exploits affecting Cisco Security Manager. Cisco has released security updates to address multiple pre-authentication remote code execution vulnerabilities with public exploits affecting Cisco Security Manager (CSM). CSM provides a comprehensive management solution for CISCO devices, including intrusion prevention systems and firewalls (i.e. Cisco ASA appliances, Cisco […]
newssecurityaffairs.comDec 7, 2020, 9:01 PM Cisco this week released advisories for three serious vulnerabilities in Security Manager that already have proof-of-concept (PoC) exploit code available online. Tracked as CVE-2020-27130 and featuring a CVSS score of 9.1, the first of the bugs is a critical-severity issue that could be abused to download arbitrary files from the affected device.
newswww.securityweek.comNov 17, 2020, 1:42 PM- Critical vulnerabilities in Cisco Security Manager fixed, researcher discloses PoCsHelp Net Security
Cisco has patched two vulnerabilities in its Cisco Security Manager solution, both of which could allow unauthenticated, remote attackers to gain access to sensitive information on an affected system. Those are part of a batch of twelve vulnerabilities flagged in July 2020 by Florian Hauser, a security researcher and red teamer at Code White. About the Cisco Security Manager vulnerabilities Cisco Security Manager is a security management application that provides insight into and control of … More →
newswww.helpnetsecurity.comNov 17, 2020, 11:49 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-59181CVSS 4.8 · Medium
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directo…
- CVE-2025-60835CVSS 7.8 · High
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
- CVE-2026-49779CVSS 6.5 · Medium
Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.
- CVE-2026-52707CVSS 8.1 · High
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
- CVE-2026-52703CVSS 9.6 · Critical
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
- CVE-2026-49112CVSS 7.5 · High
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.