Vulnerability record · CVE-2020-27128 · published 6 November 2020
CVE-2020-27128: Cisco SD-WAN vManage API path traversal allows arbitrary file write
Cisco · Sd Wan
Cisco SD-WAN vManage Software fails to properly validate requests to its application data endpoints, allowing path traversal through API calls. An authenticated remote attacker can write files to arbitrary locations on the affected system, which can undermine the integrity of the management platform.
Description
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to an arbitrary location on the targeted system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityThe flaw allows authenticated arbitrary file write on a central SD-WAN management platform and has a very high EPSS score, though it requires valid credentials and no public exploitation is documented.
What it is
Cisco SD-WAN vManage Software fails to properly validate requests to its application data endpoints, allowing path traversal through API calls. An authenticated remote attacker can write files to arbitrary locations on the affected system, which can undermine the integrity of the management platform.
Impact
The attacker gains the ability to write arbitrary files anywhere on the vManage host, enabling tampering with application or system files rather than direct data disclosure. This can lead to further compromise or disruption of the SD-WAN management plane.
Attack surface
The flaw is reached over the network through the vManage application data APIs; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates a low-complexity remote attack that requires authenticated credentials but no user interaction.
Exploitation
No public exploitation is confirmed: CVE-2020-27128 is not listed in CISA KEV and the only references are Cisco vendor advisories, though EPSS is high at roughly 0.61 (99th percentile).
What to do
- Apply the fixed vManage release from the Cisco security advisory cisco-sa-vmanage-file-Y2JSRNRb.
- Restrict network access to vManage management and API interfaces to trusted administrative networks.
- Enforce least privilege and strong authentication for vManage accounts, and audit for unnecessary accounts.
- Monitor and alert on unexpected file creation or modification in sensitive directories on vManage hosts.
Detection
- Review vManage API access logs for requests containing path traversal sequences such as ../ or encoded variants.
- Monitor file integrity on vManage hosts for new or modified files outside expected application paths.
- Alert on anomalous authenticated API activity from unusual source addresses or at unusual times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-27128 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-27128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.