← Vulnerability feed

Vulnerability record · CVE-2020-27128 · published 6 November 2020

CVE-2020-27128: Cisco SD-WAN vManage API path traversal allows arbitrary file write

Cisco · Sd Wan

Cisco SD-WAN vManage Software fails to properly validate requests to its application data endpoints, allowing path traversal through API calls. An authenticated remote attacker can write files to arbitrary locations on the affected system, which can undermine the integrity of the management platform.

6.5 CVSS 3.1 Medium EPSS 61% · top 0.9% CWE-22 · Path traversal
6.5CVSS 3.1 base score, v2 4.0
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to an arbitrary location on the targeted system.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows authenticated arbitrary file write on a central SD-WAN management platform and has a very high EPSS score, though it requires valid credentials and no public exploitation is documented.

What it is

Cisco SD-WAN vManage Software fails to properly validate requests to its application data endpoints, allowing path traversal through API calls. An authenticated remote attacker can write files to arbitrary locations on the affected system, which can undermine the integrity of the management platform.

Impact

The attacker gains the ability to write arbitrary files anywhere on the vManage host, enabling tampering with application or system files rather than direct data disclosure. This can lead to further compromise or disruption of the SD-WAN management plane.

Attack surface

The flaw is reached over the network through the vManage application data APIs; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates a low-complexity remote attack that requires authenticated credentials but no user interaction.

Exploitation

No public exploitation is confirmed: CVE-2020-27128 is not listed in CISA KEV and the only references are Cisco vendor advisories, though EPSS is high at roughly 0.61 (99th percentile).

What to do

  • Apply the fixed vManage release from the Cisco security advisory cisco-sa-vmanage-file-Y2JSRNRb.
  • Restrict network access to vManage management and API interfaces to trusted administrative networks.
  • Enforce least privilege and strong authentication for vManage accounts, and audit for unnecessary accounts.
  • Monitor and alert on unexpected file creation or modification in sensitive directories on vManage hosts.

Detection

  • Review vManage API access logs for requests containing path traversal sequences such as ../ or encoded variants.
  • Monitor file integrity on vManage hosts for new or modified files outside expected application paths.
  • Alert on anomalous authenticated API activity from unusual source addresses or at unusual times.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-27128 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-20775Cisco SD-WAN CLI access control flaw allows root privilege escalationCisco SD-WAN Software has improper access controls on commands within the application CLI, letting an authenticated local attacker run a crafted comm…KEVEPSS 12%analysed9.9CVE-2020-3374Cisco sd-wan improper authorization vulnerabilityA vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…EPSS 1.9%9.8CVE-2020-3375Cisco sd-wan memory buffer overflow vulnerabilityA vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. T…EPSS 3.9%9.8CVE-2018-15387Cisco sd-wan improper input validation vulnerabilityA vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. …EPSS 1.1%8.8CVE-2019-1624Cisco sd-wan command injection vulnerabilityA vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary c…EPSS 4.3%8.8CVE-2019-1650Cisco vedge 100 firmware improper input validation vulnerabilityA vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating s…EPSS 3.5%8.1CVE-2023-20113Cisco sd-wan cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a c…EPSS 0.26%8.0CVE-2019-1647Cisco sd-wan improper access control vulnerabilityA vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized ac…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2020-27128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.