SB2017032301 - Path traversal in Cisco IOx
Published: March 23, 2017 Updated: March 27, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Path traversal (CVE-ID: CVE-2017-3851)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to obtain potentially sensitive information on the affected device.
The weakness exists due to directory traversal in the web framework code of the Cisco application-hosting framework (CAF) component. A remote user can send specially crafted requests to the CAF component and view arbitrary files on the target virtual instance running on the affected device.
Successful exploitation of the vulnerability results in information disclosure.
Remediation
Install update from vendor's website.