SB2017032301 - Path traversal in Cisco IOx
Published: March 23, 2017 Updated: March 27, 2017
Security Bulletin ID
SB2017032301
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2017-3851)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the affected device.The weakness exists due to directory traversal in the web framework code of the Cisco application-hosting framework (CAF) component. A remote user can send specially crafted requests to the CAF component and view arbitrary files on the target virtual instance running on the affected device.
Successful exploitation of the vulnerability results in information disclosure.
Remediation
Install update from vendor's website.