Path traversal in Cisco Data Center Network Manager - CVE-2018-0464

 

Path traversal in Cisco Data Center Network Manager - CVE-2018-0464

Published: August 28, 2018 / Updated: August 29, 2018


Vulnerability identifier: #VU14549
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0464
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to conduct path traversal attack on the target system.

The vulnerability exists due to improper validation of user requests within the management interface. A remote attacker can send malicious requests containing directory traversal character sequences within the management interface and view or create arbitrary files on the targeted system.


Affected software

Cisco Data Center Network Manager

How to mitigate CVE-2018-0464

Update to version 11.0(1).

Cisco Data Center Network Manager - update to 11.0.1

External References

Related Security Bulletins