SB2018082903 - Path traversal in Cisco Data Center Network Manager
Published: August 29, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2018-0464)
The vulnerability allows a remote authenticated attacker to conduct path traversal attack on the target system.
The vulnerability exists due to improper validation of user requests within the management interface. A remote attacker can send malicious requests containing directory traversal character sequences within the management interface and view or create arbitrary files on the targeted system.
Remediation
Install update from vendor's website.