Path traversal in Cisco Network Convergence System 1000 Series - CVE-2019-1681
Published: February 22, 2019
Cisco Network Convergence System 1000 Series
Detailed vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists in the TFTP service due to input validation error when processing directory traversal sequences. A remote attacker can use directory traversal techniques in malicious requests sent to the TFTP service to retrieve arbitrary files from the targeted device.