HTTP: Cisco Prime Network Analysis Module graph sfile Directory Traversal

This signature detects attempts to exploit a known vulnerability in the Cisco Prime Network Analysis Module. Successful exploitation could allow an attacker to delete any file accessible to the web service.

Extended Description

A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests that it receives and the software does not apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to delete arbitrary files from the affected system. Cisco Bug IDs: CSCvf41365.

Affected Products

Cisco prime_network_analysis_module

References

BugTraq: 101527

CVE: CVE-2017-12285

Short Name
HTTP:DIR:CISCO-PRIME-DIR-TRAV
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Analysis CVE-2017-12285 Cisco Directory Module Network Prime Traversal bid:101527 graph sfile
Release Date
12/21/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Cisco

CVSS Score

6.4

Found a potential security threat?