Back

HIGH

Cisco Data Center Network Manager Path Traversal Vulnerability

Published Nov 18, 2024

Description

A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to overwrite or list arbitrary files on the affected device.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published Nov 18, 2024
Updated Nov 18, 2024
Reserved Dec 12, 2019
CISA Vulnrichment
Updated Nov 18, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner cisco
Published Nov 18, 2024
Updated Nov 18, 2024
Exploited since n/a
EUVD-2020-24809