CVE-2026-20062Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker with administrative privileges in one context to copy files to or from another context, including configuration files. This vulnerability is due to improper access controls for Secure Copy Protocol (SCP) operations when the CiscoSSH stack is enabled. An attacker could exploit this vulnerability by authenticating to a non-admin context of the device and issuing crafted SCP copy commands in that non-admin context. A successful exploit could allow the attacker to read, create, or overwrite sensitive files that belong to another context, including the admin and system contexts. The attacker cannot directly impact the availability of services pertaining to other contexts. To exploit this vulnerability, the attacker must have valid administrative credentials for a non-admin context. Note: An attacker cannot list or enumerate files from another context and would need to know the exact file path, which increases the complexity of a successful attack.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-279

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-04: 2Technical Details · 2026-03-04: 203-04
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20062 Cisco Secure Firewall ASA Multiple Context SCP Privilege Escalation Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20062

    Post summary

    The content announces CVE-2026-20062, detailing a privilege‑escalation issue in Cisco ASA’s SCP, but it does not provide PoC, exploit code, or mitigation information.

    0000071
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-20062 A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker w… https://www.cve.org/CVERecord?id=CVE-2026-20062

    Post summary

    The text briefly describes a CLI‑based vulnerability in Cisco ASA that permits authenticated local attackers; no PoC, exploit, patch, or active exploitation information is provided.

    00000116
    56.6K followersView on X

Explore more