CVE-2017-12285
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests that it receives and the software does not apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to delete arbitrary files from the affected system. Cisco Bug IDs: CSCvf41365.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 37.19% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-22
- Affected
- cisco/prime network analysis module
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/101527Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039623Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-namVendor Advisory
- http://www.securityfocus.com/bid/101527Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039623Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-namVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.