APP: EMC CMCNE FileUploadController Information Disclosure

This signature detects attempts to exploit a known vulnerability against EMC CMCNE FileUploadController. A successful attack can lead to unauthorized information disclosure.

Extended Description

The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to the Connectrix Manager repository, which allows remote attackers to obtain sensitive information by importing a crafted firmware file.

Affected Products

Emc connectrix_manager

References

CVE: CVE-2014-2276

Short Name
APP:EMC-CMCNE-INFO-DISC
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CMCNE CVE-2014-2276 Disclosure EMC FileUploadController Information
Release Date
04/02/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Emc

CVSS Score

5.0

Found a potential security threat?