CVE-2020-3538: Cisco Data Center Network Manager Path Traversal Vulnerability
A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to overwrite or list arbitrary files on the affected device.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3538?
CVE-2020-3538 has a medium severity rating due to its potential for exploitation via path traversal attacks.
How do I fix CVE-2020-3538?
To mitigate CVE-2020-3538, ensure that you apply the latest patches provided by Cisco for Data Center Network Manager.
What systems are affected by CVE-2020-3538?
CVE-2020-3538 affects Cisco Data Center Network Manager software versions that do not enforce adequate path restrictions.
What type of attack can CVE-2020-3538 enable?
CVE-2020-3538 can enable remote authenticated attackers to execute path traversal attacks on affected systems.
Is authentication required to exploit CVE-2020-3538?
Yes, an attacker must be authenticated to exploit CVE-2020-3538 and perform a path traversal attack.