CVE-2013-5486: OS Command Injection
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. NOTE: this can be leveraged to execute arbitrary commands by using the JBoss autodeploy functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5486?
CVE-2013-5486 is classified as a medium severity vulnerability.
How do I fix CVE-2013-5486?
To mitigate CVE-2013-5486, upgrade Cisco Prime Data Center Network Manager to version 6.2(1) or later.
What types of attacks can exploit CVE-2013-5486?
CVE-2013-5486 can be exploited by remote attackers to perform directory traversal attacks and write arbitrary files.
Which Cisco Prime Data Center Network Manager versions are affected by CVE-2013-5486?
CVE-2013-5486 affects Cisco Prime Data Center Network Manager versions 4.1(2) through 6.1(1b).
Is CVE-2013-5486 still a concern for users of Cisco Prime Data Center Network Manager?
Yes, users of affected versions should apply updates or mitigations to protect against CVE-2013-5486.