CVE-2018-0258: Path Traversal
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network Manager (DCNM) Version 10.0 and later, and Cisco Prime Infrastructure (PI) All versions. Cisco Bug IDs: CSCvf32411, CSCvf81727.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0258?
CVE-2018-0258 is a vulnerability in the Cisco Prime File Upload servlet that allows a remote attacker to upload arbitrary files to any directory of a vulnerable device and execute those files.
Which Cisco products are affected by CVE-2018-0258?
Cisco Prime Data Center Network Manager versions 10.0(1) and 10.2(1), as well as Cisco Prime Infrastructure version 3.3(0.0), are affected by CVE-2018-0258.
What is the severity of CVE-2018-0258?
CVE-2018-0258 has a severity score of 9.8, which is considered critical.
How can an attacker exploit CVE-2018-0258?
An attacker can exploit CVE-2018-0258 by uploading arbitrary files to a vulnerable device, which allows them to execute those files and potentially gain control over the device.
Where can I find more information about CVE-2018-0258?
You can find more information about CVE-2018-0258 on the Cisco Security Advisory page and the Tenable Research page.