A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network Manager (DCNM) Version 10.0 and later, and Cisco Prime Infrastructure (PI) All versions. Cisco Bug IDs: CSCvf32411, CSCvf81727.
2018-05-02T22:29:00.793
2024-11-21T03:37:49.960
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | prime_data_center_network_manager | 10.0\(1\) | Yes |
Application | cisco | prime_data_center_network_manager | 10.2\(1\) | Yes |
Application | cisco | prime_infrastructure | 3.3\(0.0\) | Yes |