A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system. The vulnerability is due to improper validation of user requests within the management interface. An attacker could exploit this vulnerability by sending malicious requests containing directory traversal character sequences within the management interface. An exploit could allow the attacker to view or create arbitrary files on the targeted system.
oryginał ENCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NCisco Prime Data Center Network Manager
APPCisco10.010.110.210.3\(1\)6.3\(1\)6.3\(2\)7.0\(1\)7.0\(2\)7.1\(1\)
Powiązane podatności
Cisco Prime — path traversal i zdalne wykonanie kodu przez upload pliku
RCE z uprawnieniami root w Cisco Prime DCNM — brak uwierzytelnienia narzędzia debug
Cisco Prime DCNM — domyślne statyczne hasło umożliwia pełny dostęp administracyjny
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) be...
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Networ...