This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:DIR:CISCO-PRIME-EPNM-DIR
|
Severity |
Minor
|
Recommended |
Yes
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Cisco Prime Infrastructure and EPNM Directory Traversal
|
Release Date |
2019/06/24
|
Update Number |
3183
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Cisco Prime Infrastructure and EPNM Directory Traversal
This signature detects attempts to exploit a known vulnerability against Cisco Prime Infrastructure and EPNM. A successful attack can lead to Directory Traversal.
Extended Description
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view application files that may contain sensitive information.
Affected Products
- Cisco evolved_programmable_network_manager 1.1
- Cisco evolved_programmable_network_manager 1.1.2
- Cisco evolved_programmable_network_manager 1.2
- Cisco evolved_programmable_network_manager 1.2.1.3
- Cisco evolved_programmable_network_manager 1.2.200
- Cisco evolved_programmable_network_manager 1.2.300
- Cisco evolved_programmable_network_manager 1.2.400
- Cisco evolved_programmable_network_manager 1.2.500
- Cisco evolved_programmable_network_manager 1.2.600
- Cisco evolved_programmable_network_manager 1.2.700
- Cisco evolved_programmable_network_manager 2.0
- Cisco evolved_programmable_network_manager 2.0.1
- Cisco evolved_programmable_network_manager 2.0.2
- Cisco evolved_programmable_network_manager 2.0.3
- Cisco evolved_programmable_network_manager 2.0.4
- Cisco evolved_programmable_network_manager 2.0(4.0.45b)
- Cisco evolved_programmable_network_manager 2.1
- Cisco evolved_programmable_network_manager 2.1.1
- Cisco evolved_programmable_network_manager 2.1.2
- Cisco evolved_programmable_network_manager 2.1.3
- Cisco evolved_programmable_network_manager 2.2
- Cisco evolved_programmable_network_manager 2.2.1
- Cisco evolved_programmable_network_manager 3.0.0
- Cisco prime_infrastructure -
- Cisco prime_infrastructure 1.1
- Cisco prime_infrastructure 1.2
- Cisco prime_infrastructure 1.2.0
- Cisco prime_infrastructure 1.2.0.103
- Cisco prime_infrastructure 1.2.1
- Cisco prime_infrastructure 1.2.12
- Cisco prime_infrastructure 1.3
- Cisco prime_infrastructure 1.3.0
- Cisco prime_infrastructure 1.3.0.20
- Cisco prime_infrastructure 1.3.0.20-2
- Cisco prime_infrastructure 1.4
- Cisco prime_infrastructure 1.4.0
- Cisco prime_infrastructure 1.4.0.45
- Cisco prime_infrastructure 1.4.0.45-2
- Cisco prime_infrastructure 1.4.1
- Cisco prime_infrastructure 2.0
- Cisco prime_infrastructure 2.0.0
- Cisco prime_infrastructure 2.0.0.0.294-2
- Cisco prime_infrastructure 2.0.0.30
- Cisco prime_infrastructure 2.1
- Cisco prime_infrastructure 2.1.1
- Cisco prime_infrastructure 2.1.2
- Cisco prime_infrastructure 2.2
- Cisco prime_infrastructure 2.2.0
- Cisco prime_infrastructure 2.2.1
- Cisco prime_infrastructure 2.2.2
- Cisco prime_infrastructure 2.2(2)
- Cisco prime_infrastructure 2.2.3
- Cisco prime_infrastructure 3.0
- Cisco prime_infrastructure 3.0.0
- Cisco prime_infrastructure 3.0.1
- Cisco prime_infrastructure 3.0.2
- Cisco prime_infrastructure 3.0.3
- Cisco prime_infrastructure 3.0_base
- Cisco prime_infrastructure 3.1
- Cisco prime_infrastructure 3.1.0
- Cisco prime_infrastructure 3.1.1
- Cisco prime_infrastructure 3.1.3
- Cisco prime_infrastructure 3.1.4
- Cisco prime_infrastructure 3.1.5
- Cisco prime_infrastructure 3.1.6
- Cisco prime_infrastructure 3.1.7
- Cisco prime_infrastructure 3.1_base
- Cisco prime_infrastructure 3.2
- Cisco prime_infrastructure 3.2.0
- Cisco prime_infrastructure 3.2.1
- Cisco prime_infrastructure 3.2(1.0)
- Cisco prime_infrastructure 3.2.2
- Cisco prime_infrastructure 3.2(2.0)
- Cisco prime_infrastructure 3.3
- Cisco prime_infrastructure 3.3(0.0)
- Cisco prime_infrastructure 3.3.1
References