CVE-2015-0666: Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.
Other sources
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0666?
CVE-2015-0666 has a medium severity rating due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2015-0666?
To fix CVE-2015-0666, update Cisco Prime Data Center Network Manager to version 7.1(1) or later.
Which products are affected by CVE-2015-0666?
CVE-2015-0666 affects versions of Cisco Prime Data Center Network Manager including versions 6.3(1), 6.3(2), and 7.0(1) and earlier.
Can CVE-2015-0666 be exploited remotely?
Yes, CVE-2015-0666 can be exploited remotely by attackers to read arbitrary files through crafted pathnames.
What is the potential impact of CVE-2015-0666?
The potential impact of CVE-2015-0666 includes unauthorized access to sensitive file data, which can lead to further system compromise.