PT-2017-3726 · Cisco · Cisco Prime File Upload Servlet+2

Publicado

2017-07-13

·

Atualizado

2019-10-09

·

CVE-2018-0258

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco Prime Data Center Network Manager versions 10.0 and later Cisco Prime Infrastructure all versions
Description: A vulnerability in the Cisco Prime File Upload servlet could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device and execute those files due to path traversal issues and lack of restrictions on uploading dangerous file types.
Recommendations: For Cisco Prime Data Center Network Manager versions 10.0 and later, update to a version that includes the fix for the identified bug IDs. For Cisco Prime Infrastructure all versions, update to a version that includes the fix for the identified bug IDs. As a temporary workaround, consider restricting access to the file upload functionality until a patch is available.

Correção

Unrestricted File Upload

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01583
CVE-2018-0258

Produtos afetados

Cisco Prime Data Center Network Manager
Cisco Prime File Upload Servlet
Cisco Prime Infrastructure