Skip to content

Commit 4a8af3e

Browse files
committed
Update taxonomy
1 parent 6a59906 commit 4a8af3e

File tree

1 file changed

+45
-0
lines changed

1 file changed

+45
-0
lines changed

taxonomy/scenarios.json

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3864,6 +3864,51 @@
38643864
"CWE-78"
38653865
]
38663866
},
3867+
"crowdsecurity/vpatch-CVE-2026-20127-dca-disclosure": {
3868+
"name": "crowdsecurity/vpatch-CVE-2026-20127-dca-disclosure",
3869+
"description": "Detects unauthenticated access to the DCA credential file in Cisco Catalyst SD-WAN Manager (CVE-2026-20127)",
3870+
"label": "Cisco SD-WAN vManage - Credentials Disclosure",
3871+
"behaviors": [
3872+
"http:exploit"
3873+
],
3874+
"mitre_attacks": [
3875+
"TA0001:T1190"
3876+
],
3877+
"confidence": 3,
3878+
"spoofable": 0,
3879+
"cti": true,
3880+
"service": "http",
3881+
"created_at": "2026-03-06T10:00:35",
3882+
"cves": [
3883+
"CVE-2026-20127"
3884+
],
3885+
"cwes": [
3886+
"CWE-552"
3887+
]
3888+
},
3889+
"crowdsecurity/vpatch-CVE-2026-20127": {
3890+
"name": "crowdsecurity/vpatch-CVE-2026-20127",
3891+
"description": "Detects path traversal file upload exploitation in Cisco Catalyst SD-WAN Manager (CVE-2026-20127)",
3892+
"label": "Cisco SD-WAN vManage - RCE",
3893+
"behaviors": [
3894+
"http:exploit"
3895+
],
3896+
"mitre_attacks": [
3897+
"TA0001:T1190"
3898+
],
3899+
"confidence": 3,
3900+
"spoofable": 0,
3901+
"cti": true,
3902+
"service": "http",
3903+
"created_at": "2026-03-06T10:00:35",
3904+
"cves": [
3905+
"CVE-2026-20127"
3906+
],
3907+
"cwes": [
3908+
"CWE-22",
3909+
"CWE-434"
3910+
]
3911+
},
38673912
"crowdsecurity/vpatch-CVE-2026-23744": {
38683913
"name": "crowdsecurity/vpatch-CVE-2026-23744",
38693914
"description": "Detects RCE in MCPJam Inspector via crafted POST to /api/mcp/connect",

0 commit comments

Comments
 (0)