Path traversal in Cisco Data Center Network Manager - CVE-2019-15982

 

Path traversal in Cisco Data Center Network Manager - CVE-2019-15982

Published: January 7, 2020


Vulnerability identifier: #VU23990
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15982
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists in the Application Framework feature due to input validation error when processing directory traversal sequences within the "AFW Image Upload" component. A remote administrator can send a specially crafted HTTP request and execute arbitrary files on the system.


Affected software

Cisco Data Center Network Manager

How to mitigate CVE-2019-15982

Install update from vendor's website.

Cisco Data Center Network Manager - update to 11.3.1

External References

Related Security Bulletins