Ad

CVE-2026-76433

MEDIUM CVSS 3.1: 5,3 EPSS 0.93%
Обновлено 18 сентября 2026
Cisco
Параметр Значение
CVSS 5,3 (MEDIUM)
Тип уязвимости CWE-22 (Обход пути)
Поставщик Cisco
Публичный эксплойт Нет

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory traversal character sequences in a user-supplied path when the software processes provisioning resource requests. An attacker could exploit this vulnerability by sending a crafted request to the provisioning download service.

A successful exploit could allow the attacker to access protected files without authentication, potentially exposing sensitive information.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Нужны права
Не требуются
Права не нужны
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Нет
Нет утечки данных
Целостность
Низкое
Частичная модификация данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v3.1

Тип уязвимости (CWE)