Cisco Prime Data Center Network Manager File Upload RCE (cisco-sa-20180502-prime-upload)

Critical Nessus Plugin ID 110518

Synopsis

A network management system running on the remote host is affected by a remote code execution vulnerability.

Description

The Cisco Prime Data Center Network Manager (DCNM) running on the remote host is affected by a remote code execution vulnerability due to improper input validation of the parameters in an HTTP request processed by the XmpFileUploadServlet servlet. An unauthenticated, remote attacker can exploit this issue, via a specially crafted HTTP request, to upload a Java Server Pages (JSP) file to a specific folder using path traversal techniques and then execute that file remotely. An exploit could allow the attacker to execute arbitrary commands on the affected device with the privileges of the SYSTEM user

Solution

Upgrade to Cisco Prime Data Center Network Manager version 10.3(1) or later.

See Also

http://www.nessus.org/u?e1ab861c

Plugin Details

Severity: Critical

ID: 110518

File Name: cisco_dcnm_cve-2018-0258.nasl

Version: 1.1

Type: remote

Family: CISCO

Published: 2018/06/13

Updated: 2018/06/13

Dependencies: 11936, 67246

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:cisco:prime_data_center_network_manager

Required KB Items: installed_sw/cisco_dcnm_web

Patch Publication Date: 2018/05/02

Vulnerability Publication Date: 2018/05/02

Reference Information

CVE: CVE-2018-0258

BID: 104074