Cisco IoT Field Network Director Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in the web-based management interface of Cisco IoT Field Network Director. This vulnerability allows an authenticated, remote attacker with low privileges to access files that they are not authorized to retrieve. The issue arises from inadequate file access validation, enabling attackers to exploit the vulnerability by sending crafted input through the management interface. Successful exploitation could result in unauthorized file access.

Impact

Exploitation of this vulnerability could lead to unauthorized access to files that the attacker does not have permission to view.

Remediation

Cisco has released software updates to address this vulnerability. Users should upgrade to version 5.0.0-117 or migrate to a supported release that includes the fix. For more information on Cisco software releases, consult the Cisco Security Vulnerability Policy.

Added: May 6, 2026, 6:53 PM
Updated: May 6, 2026, 6:53 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.6
exploitability
5.2
remediation
7.7
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.