Cisco DCNM Software Vulnerability: Path Traversal Attacks Ahead
CVE-2020-3538
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 18 November 2024
What is CVE-2020-3538?
A security vulnerability exists in a specific REST API endpoint of Cisco Data Center Network Manager (DCNM) Software, enabling an authenticated remote attacker to conduct path traversal attacks. This issue arises from inadequate enforcement of path restrictions within the API. An attacker could exploit this flaw by sending specially crafted HTTP requests, which may allow them to overwrite or list arbitrary files on the affected device. To mitigate this threat, Cisco has provided software updates designed to resolve the vulnerability. There are currently no alternative workarounds available to address this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Data Center Network Manager
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved