PT-2020-1365 · Cisco · Cisco Data Center Network Manager
Published
2020-01-02
·
Updated
2020-01-08
·
CVE-2019-15982
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Data Center Network Manager (DCNM) versions prior to the fixed version
Description
The issue exists due to incorrect restriction of a directory path name with limited access in the Application Framework component of Cisco Data Center Network Manager (DCNM). This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device, requiring administrative privileges on the DCNM application.
Recommendations
For versions prior to the fixed version, update to the fixed version to resolve the issue.
As a temporary workaround, consider restricting access to the Application Framework feature and the REST and SOAP API endpoints to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Data Center Network Manager