HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2018-0464

CVSS 8.1v3.0pub. 2018-10-05upd. 2024-11-21

A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system. The vulnerability is due to improper validation of user requests within the management interface. An attacker could exploit this vulnerability by sending malicious requests containing directory traversal character sequences within the management interface. An exploit could allow the attacker to view or create arbitrary files on the targeted system.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Cisco Prime Data Center Network Manager

    APP
    Cisco
    10.010.110.210.3\(1\)6.3\(1\)6.3\(2\)7.0\(1\)7.0\(2\)7.1\(1\)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2018-0258CRITICAL9.8PL ✓same product

Cisco Prime — path traversal i zdalne wykonanie kodu przez upload pliku

CVE-2017-6639CRITICAL9.8PL ✓same product

RCE z uprawnieniami root w Cisco Prime DCNM — brak uwierzytelnienia narzędzia debug

CVE-2017-6640CRITICAL9.8PL ✓same product

Cisco Prime DCNM — domyślne statyczne hasło umożliwia pełny dostęp administracyjny

CVE-2015-0666HIGH7.5⚠ KEVsame product

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) be...

CVE-2013-5486HIGH10.0same product

Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Networ...