Lucene search

K
ciscoCiscoCISCO-SA-20150401-DCNM
HistoryApr 01, 2015 - 4:00 p.m.

Cisco Prime Data Center Network Manager File Information Disclosure Vulnerability

2015-04-0116:00:00
tools.cisco.com
12

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

EPSS

0.973

Percentile

99.9%

Cisco Prime Data Center Network Manager (DCNM) contains a file information disclosure vulnerability that could allow an unauthenticated, remote attacker to retrieve arbitrary files from the underlying operating system.

Cisco has released software updates that address this vulnerability.

Workarounds that mitigate this vulnerability are not available.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150401-dcnm [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150401-dcnm”]

Affected configurations

Vulners
Node
ciscoprime_data_center_network_managerMatchany
OR
ciscoprime_data_center_network_managerMatchany
VendorProductVersionCPE
ciscoprime_data_center_network_manageranycpe:2.3:a:cisco:prime_data_center_network_manager:any:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

EPSS

0.973

Percentile

99.9%