216.73.217.22

CVE-2026-20160

· Published 01/04/2026 17:28 · Modified 01/04/2026 17:28

Labels: CVE-2026-20160 2026-04-01CVE-2026-20160CWE-668[email protected]

Essential information

Published
01/04/2026 17:28
Modified
01/04/2026 17:28
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cisco / smart software manager on-prem cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:*

References