Lucene search

K
ciscoCiscoCISCO-SA-20171018-NAM
HistoryOct 18, 2017 - 4:00 p.m.

Cisco Network Analysis Module Parameter Directory Traversal Arbitrary File Deletion Vulnerability

2017-10-1816:00:00
tools.cisco.com
23

EPSS

0.965

Percentile

99.6%

A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system.

The vulnerability exists because the affected software does not perform proper input validation of HTTP requests that it receives and the software does not apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to delete arbitrary files from the affected system.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-nam [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-nam”]

Affected configurations

Vulners
Node
ciscoprime_network_analysis_module_softwareMatchany
OR
ciscoprime_network_analysis_module_softwareMatchany
VendorProductVersionCPE
ciscoprime_network_analysis_module_softwareanycpe:2.3:a:cisco:prime_network_analysis_module_software:any:*:*:*:*:*:*:*

EPSS

0.965

Percentile

99.6%