First published: Mon Sep 23 2013(Updated: )
Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCud80148.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Data Center Network Manager (DCNM) | <=6.1\(1b\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2e\) | |
Cisco Prime Data Center Network Manager (DCNM) | =6.1\(1a\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.1\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.1\(3\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.1\(4\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.1\(5\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.2\(1\) | |
Cisco Prime Data Center Network Manager (DCNM) | =4.2\(3\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.0\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.0\(3\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.1\(1\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.1\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.1\(3u\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2a\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2b\) | |
Cisco Prime Data Center Network Manager (DCNM) | =5.2\(2c\) | |
Cisco Prime Data Center Network Manager (DCNM) | =6.1\(1b\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5490 is classified as a medium severity vulnerability.
To fix CVE-2013-5490, upgrade to Cisco Prime Data Center Network Manager version 6.2(1) or later.
CVE-2013-5490 can be exploited through XML External Entity (XXE) attacks allowing remote attackers to read arbitrary text files.
CVE-2013-5490 affects multiple versions including 4.1(2), 4.1(3), 5.1(1), and earlier versions up to 6.1(1b).
Yes, CVE-2013-5490 is remotely exploitable by attackers via specially crafted XML requests.