Path traversal in Cisco Data Center Network Manager - CVE-2019-15982

 

Path traversal in Cisco Data Center Network Manager - CVE-2019-15982

Published: January 7, 2020


Vulnerability identifier: #VU23990
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-15982
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco Data Center Network Manager

Detailed vulnerability description

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists in the Application Framework feature due to input validation error when processing directory traversal sequences within the "AFW Image Upload" component. A remote administrator can send a specially crafted HTTP request and execute arbitrary files on the system.


How to mitigate CVE-2019-15982

Install update from vendor's website.

Sources