#VU23990 Path traversal in Cisco Data Center Network Manager - CVE-2019-15982

 

#VU23990 Path traversal in Cisco Data Center Network Manager - CVE-2019-15982

Published: January 7, 2020


Vulnerability identifier: #VU23990
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-15982
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Data Center Network Manager
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists in the Application Framework feature due to input validation error when processing directory traversal sequences within the "AFW Image Upload" component. A remote administrator can send a specially crafted HTTP request and execute arbitrary files on the system.


Remediation

Install update from vendor's website.

External links