Path traversal in Cisco Network Convergence System 1000 Series - CVE-2019-1681

 

Path traversal in Cisco Network Convergence System 1000 Series - CVE-2019-1681

Published: February 22, 2019


Vulnerability identifier: #VU17845
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1681
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists in the TFTP service due to input validation error when processing directory traversal sequences. A remote attacker can use directory traversal techniques in malicious requests sent to the TFTP service to retrieve arbitrary files from the targeted device.


Affected software

Cisco Network Convergence System 1000 Series

How to mitigate CVE-2019-1681

Update to version 7.0.1.19, 6.6.11.12, 6.6.1.19, 6.5.2.10 or 6.5.2.9.

Cisco Network Convergence System 1000 Series - addressed in versions 6.5.2.9, 6.5.2.10, 6.6.1.19, 6.6.11.12, 7.0.1.19

External References

Related Security Bulletins