First published: Fri Apr 03 2015(Updated: )
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Data Center Network Manager | ||
Cisco Prime Data Center Network Manager (DCNM) | <=7.0\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =6.3\(1\) | |
Cisco Prime Data Center Network Manager (DCNM) | =6.3\(2\) | |
Cisco Prime Data Center Network Manager (DCNM) | =7.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0666 has a medium severity rating due to its potential to allow unauthorized access to sensitive files.
To fix CVE-2015-0666, update Cisco Prime Data Center Network Manager to version 7.1(1) or later.
CVE-2015-0666 affects versions of Cisco Prime Data Center Network Manager including versions 6.3(1), 6.3(2), and 7.0(1) and earlier.
Yes, CVE-2015-0666 can be exploited remotely by attackers to read arbitrary files through crafted pathnames.
The potential impact of CVE-2015-0666 includes unauthorized access to sensitive file data, which can lead to further system compromise.