First published: Wed May 02 2018(Updated: )
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network Manager (DCNM) Version 10.0 and later, and Cisco Prime Infrastructure (PI) All versions. Cisco Bug IDs: CSCvf32411, CSCvf81727.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Data Center Network Manager | =10.0\(1\) | |
Cisco Prime Data Center Network Manager | =10.2\(1\) | |
Cisco Prime Infrastructure | =3.3\(0.0\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0258 is a vulnerability in the Cisco Prime File Upload servlet that allows a remote attacker to upload arbitrary files to any directory of a vulnerable device and execute those files.
Cisco Prime Data Center Network Manager versions 10.0(1) and 10.2(1), as well as Cisco Prime Infrastructure version 3.3(0.0), are affected by CVE-2018-0258.
CVE-2018-0258 has a severity score of 9.8, which is considered critical.
An attacker can exploit CVE-2018-0258 by uploading arbitrary files to a vulnerable device, which allows them to execute those files and potentially gain control over the device.
You can find more information about CVE-2018-0258 on the Cisco Security Advisory page and the Tenable Research page.