GHSA-m776-2hwc-9x9m · Severity: high — A vulnerability in the connection-handling mechanism of Cisco Crosswork Network Controller (CNC)...
Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT). Upon further analysis, the Cisco PSIRT has reclassified this issue as a customer-configurable, resource management issue rather than a security vulnerability.
Conclusion & alert: CVE-2026-20188 is rated Low Risk (22.7/100): low exploitation likelihood (EPSS 0.31%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.04% | 0.31% | +0.27% |
| 2 | 2026-05-15 | 0.11% | 0.04% | -0.07% |
| 3 | 2026-05-07 | — | 0.11% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 0.0 | 3.1 | NONE |
|
3.9 | 0.0 | [email protected] |
GHSA-m776-2hwc-9x9m · Severity: high — A vulnerability in the connection-handling mechanism of Cisco Crosswork Network Controller (CNC)...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||