PT-2020-5079 · Cisco · Cisco Nexus Data Broker
Published
2020-10-07
·
Updated
2020-10-30
·
CVE-2020-3597
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus Data Broker (affected versions not specified)
Description
The issue is related to insufficient validation of configuration backup files in the configuration restore feature. This could allow a remote attacker to perform a directory traversal attack, potentially overwriting arbitrary files accessible through the affected software. The attacker could exploit this by persuading an administrator to restore a crafted configuration backup file.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Nexus Data Broker