Network Driver Vulnerability in Cisco Terminal Service Agent
CVE-2026-20028

5MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
5 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20028?

A vulnerability in Cisco's Terminal Service Agent allows an authenticated remote attacker to bypass firewall rules tied to their user account. This issue arises from an improper association between network connections and user accounts. By sending specially crafted network traffic, an attacker with basic user credentials can exploit this vulnerability to inherit firewall privileges of other users on the system, potentially leading to unauthorized access and data exposure.

Affected Version(s)

Cisco Terminal Services Agent TSAgent-1.3

Cisco Terminal Services Agent TSAgent-1.4.2

Cisco Terminal Services Agent TSAgent-1.2

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.