First published: Mon Sep 23 2013(Updated: )
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. NOTE: this can be leveraged to execute arbitrary commands by using the JBoss autodeploy functionality.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Data Center Network Manager (DCNM) | =4.1\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.1\(3\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.1\(4\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.1\(5\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.2\(1\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.2\(3\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.0\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.0\(3\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.1\(1\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.1\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.1\(3u\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2a\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2b\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2c\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2e\) | |
Cisco Prime Data Center Network Manager (DCNM) | =6.1\(1a\) | |
Cisco Prime Data Center Network Manager (DCNM) | =6.1\(1b\) | |
Cisco Prime Data Center Network Manager (DCNM) | <=6.1\(1b\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5486 is classified as a medium severity vulnerability.
To mitigate CVE-2013-5486, upgrade Cisco Prime Data Center Network Manager to version 6.2(1) or later.
CVE-2013-5486 can be exploited by remote attackers to perform directory traversal attacks and write arbitrary files.
CVE-2013-5486 affects Cisco Prime Data Center Network Manager versions 4.1(2) through 6.1(1b).
Yes, users of affected versions should apply updates or mitigations to protect against CVE-2013-5486.