#VU23990 Path traversal in Cisco Data Center Network Manager - CVE-2019-15982
Published: January 7, 2020
Cisco Data Center Network Manager
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists in the Application Framework feature due to input validation error when processing directory traversal sequences within the "AFW Image Upload" component. A remote administrator can send a specially crafted HTTP request and execute arbitrary files on the system.