CVE-2026-20062

7.2

Cisco · Secure Firewall Adaptive Security Appliance (ASA) Software

A vulnerability in the Cisco ASA CLI allows an authenticated administrator in one context to read, create, or overwrite sensitive files in other contexts via crafted Secure Copy Protocol commands.

Executive summary

A high-severity file access vulnerability in Cisco Secure Firewall ASA software allows authenticated attackers to bypass context isolation, potentially exposing sensitive configuration data.

Vulnerability

This flaw, identified as CWE-279, stems from improper access controls for Secure Copy Protocol operations. It requires an attacker to possess valid administrative credentials for a non-admin context to execute crafted commands against other contexts.

Business impact

The vulnerability allows an attacker to manipulate files across security contexts, which could lead to unauthorized disclosure or modification of critical network configurations. Given the CVSS score of 7.2, this represents a significant risk to the integrity and confidentiality of security appliances. While the attack requires knowledge of specific file paths and administrative access to a sub-context, the potential for cross-context compromise threatens the foundation of multi-tenant security segmentation.

Remediation

Immediate Action: Review the official Cisco security advisory for the latest software releases and apply the recommended firmware updates to all affected ASA instances.

Proactive Monitoring: Audit access logs for unusual Secure Copy Protocol activity and monitor for unauthorized attempts to access sensitive configuration file paths.

Compensating Controls: Strictly limit administrative access to individual contexts and enforce the principle of least privilege for all device management accounts.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing Cisco Secure Firewall ASA in multiple context mode should prioritize this update to maintain strict logical isolation between environments. Given the potential for configuration manipulation, patching is the most reliable method to remediate this access control flaw and ensure the integrity of the security appliance.

More Cisco CVEs

Sources