You are here
Home > Preporuke > Ranjivost Cisco Data Center Network Manager softvera

Ranjivost Cisco Data Center Network Manager softvera

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

Cisco Security Advisory: Cisco Data Center Network Manager Path Traversal Vulnerability

Advisory ID: cisco-sa-20180828-dcnm-traversal

Revision: 1.0

For Public Release: 2018 August 28 21:00 GMT

Last Updated: 2018 August 28 21:00 GMT

CVE ID(s): CVE-2018-0464

CVSS Score v(3): 8.1 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

+———————————————————————

Summary

=======

A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system.

The vulnerability is due to improper validation of user requests within the management interface. An attacker could exploit this vulnerability by sending malicious requests containing directory traversal character sequences within the management interface. An exploit could allow the attacker to view or create arbitrary files on the targeted system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180828-dcnm-traversal [“https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180828-dcnm-traversal”]

—–BEGIN PGP SIGNATURE—–

iQJ5BAEBAgBjBQJbhbnKXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50
IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly
dEBjaXNjby5jb20+AAoJEJa12PPJBfcz7NUP/1ByurEVz1l/8PhzGZz14C5AFzYQ
rM9BM0hgA6LAOGdCRpYXOIW4TMibaIiz42aL7UJlw9ese3pJjA50SbLxy1cVbHkB
KENpgw+lXxl6+X5HhO2yURGvNspobUjsWk1e/HeAeqKE+lOwbgCOcHhn9LLZMhYL
ksRn9Syd2gYcFaUY+Zh6AOlIJhObW9tmF+hUbvisdHFEIPL2xIGXrcsTAYXY1vcE
3YBL5GcU54x5ALs2HVu8JczWPWhQC/pWLNeKsdi5XJus3I0aYvAQsGmld83SkEk+
jl+5Dl1eTlLnm0S5iwV2rlrPrZoGzGzpgJKaOby5JOkMedXV3CZ7K7IJ5tBXt1ia
B5j3wBEwZ4xPCetuckaUEg+MAEoBKRow6RSrxlpeh+VopknBhtWT923yfhNB/Cbe
VBy2+FrRNJuEWkOXTf0Z1ofIJGSdZkZmakpBu+PPNC3gjTr6UHEnAeDT/7gSExZU
tTUrrhOzahS+3I7865NiC93lRz/BqaZt38qd9NMKQ7eeez3tKcb7eFcHZgb4NEtV
aepHk8rF8iJ4LgOV4+dQR4o+KENP7AiXd5qJdB1IuuazC87mO1M5JHHrBQLJTSFM
fBX0AaZVeeF2AJPKQhDtRCZOhdAPYAJ+QLQP3ViNJQ0soUQaWm1q8ZYoZ2yDYn9f
YKBsh84BFhmo7deK
=io/g
—–END PGP SIGNATURE—–

_______________________________________________
cust-security-announce mailing list
cust-security-announce@cisco.com
To unsubscribe, send the command “unsubscribe” in the subject of your message to cust-security-announce-leave@cisco.com

Top
More in Preporuke
Sigurnosni nedostaci jezgre operacijskog sustava

Otkriveni su sigurnosni nedostaci jezgre operacijskog sustava Ubuntu. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja, otkrivanje osjetljivih informacija, izvršavanje...

Close