SB2017032301 - Path traversal in Cisco IOx



SB2017032301 - Path traversal in Cisco IOx

Published: March 23, 2017 Updated: March 27, 2017

Security Bulletin ID SB2017032301
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2017-3851)

The vulnerability allows a remote attacker to obtain potentially sensitive information on the affected device.

The weakness exists due to directory traversal in the web framework code of the Cisco application-hosting framework (CAF) component. A remote user can send specially crafted requests to the CAF component and view arbitrary files on the target virtual instance running on the affected device.

Successful exploitation of the vulnerability results in information disclosure.

Remediation

Install update from vendor's website.