- Description
- Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to "invalid directory permissions."
- Source
- ykramarz@cisco.com
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 9
- Impact score
- 10
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:C/I:C/A:C
- nvd@nist.gov
- CWE-22
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:application_control_engine_device_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D4DDB47-1E38-47B5-A77E-B967A0C11ADB",
"versionEndIncluding": "1.2"
},
{
"criteria": "cpe:2.3:a:cisco:application_control_engine_device_manager:1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A02EE9C-8E93-409E-823A-08C8C9ADE002"
},
{
"criteria": "cpe:2.3:a:cisco:application_networking_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E917E6B-F744-49D3-8516-132C8684F3D4",
"versionEndIncluding": "1.2"
},
{
"criteria": "cpe:2.3:a:cisco:application_networking_manager:1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E427057-56BC-4E7C-8DBA-0388A6C81C87"
}
],
"operator": "OR"
}
]
}
]