---
cve: "CVE-2026-20303"
severity: "CRITICAL"
cvss: 9.9
epss: "31%"
vendor: "Cisco"
kev: false
exploited: false
published: "2026-08-05 17:16:50"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-04T20:27:45+02:00"
---

# CVE-2026-20303

> 9.9 CRITICAL

## Beschreibung

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-20** — Improper Input Validation
  The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

## Angriffsmuster (CAPEC)

- [CAPEC-10 — Buffer Overflow via Environment Variables](https://capec.mitre.org/data/definitions/10.html) _(Severity: High)_
- [CAPEC-13 — Subverting Environment Variable Values](https://capec.mitre.org/data/definitions/13.html) _(Severity: Very High)_
- [CAPEC-101 — Server Side Include (SSI) Injection](https://capec.mitre.org/data/definitions/101.html) _(Severity: High)_
- [CAPEC-104 — Cross Zone Scripting](https://capec.mitre.org/data/definitions/104.html) _(Severity: High)_
- [CAPEC-108 — Command Line Execution through SQL Injection](https://capec.mitre.org/data/definitions/108.html) _(Severity: Very High)_
- [CAPEC-109 — Object Relational Mapping Injection](https://capec.mitre.org/data/definitions/109.html) _(Severity: High)_
- [CAPEC-110 — SQL Injection through SOAP Parameter Tampering](https://capec.mitre.org/data/definitions/110.html) _(Severity: Very High)_
- [CAPEC-120 — Double Encoding](https://capec.mitre.org/data/definitions/120.html) _(Severity: Medium)_

## ATT&CK-Techniken

- [T1562.003 — Impair Defenses:Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
- [T1574.006 — Hijack Execution Flow:Dynamic Linker Hijacking](https://attack.mitre.org/techniques/T1574/006/)
- [T1574.007 — Hijack Execution Flow:Path Interception by PATH Environment ](https://attack.mitre.org/techniques/T1574/007/)

## Referenzen

- <https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K>
- <https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-20303) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
