HIGH✓ PATCH🇬🇧 English

CVE-2018-0464

CVSS 8.1v3.0pub. 2018-10-05upd. 2024-11-21

A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system. The vulnerability is due to improper validation of user requests within the management interface. An attacker could exploit this vulnerability by sending malicious requests containing directory traversal character sequences within the management interface. An exploit could allow the attacker to view or create arbitrary files on the targeted system.

oryginał EN
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Cisco Prime Data Center Network Manager

    APP
    Cisco
    10.010.110.210.3\(1\)6.3\(1\)6.3\(2\)7.0\(1\)7.0\(2\)7.1\(1\)
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Path Traversal
CWE
Referencje

Powiązane podatności

CVE-2018-0258CRITICAL9.8PL ✓ten sam produkt

Cisco Prime — path traversal i zdalne wykonanie kodu przez upload pliku

CVE-2017-6639CRITICAL9.8PL ✓ten sam produkt

RCE z uprawnieniami root w Cisco Prime DCNM — brak uwierzytelnienia narzędzia debug

CVE-2017-6640CRITICAL9.8PL ✓ten sam produkt

Cisco Prime DCNM — domyślne statyczne hasło umożliwia pełny dostęp administracyjny

CVE-2015-0666HIGH7.5⚠ KEVten sam produkt

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) be...

CVE-2013-5486HIGH10.0ten sam produkt

Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Networ...