PT-2015-4793 · Cisco · Cisco Prime Data Center Network Manager
CVE-2015-0666
·
Publicado
2015-04-03
·
Atualizado
2024-12-19
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Prime Data Center Network Manager (DCNM) versions prior to 7.1(1)
Description
The issue allows remote attackers to read arbitrary files via a crafted pathname. This is due to a directory traversal vulnerability in the fmserver servlet.
Recommendations
For versions prior to 7.1(1), update to version 7.1(1) or later to resolve the issue. As a temporary workaround, consider restricting access to the fmserver servlet to minimize the risk of exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Prime Data Center Network Manager