A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data.
This vulnerability exists because the web-management interface and certain HTTP-based APIs do not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cisco
Cisco network Services Orchestrator |
|
CPEs | cpe:2.3:a:cisco:network_services_orchestrator:5.3.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:network_services_orchestrator:5.4.0.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:network_services_orchestrator:5.4.0.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:network_services_orchestrator:5.4:*:*:*:*:*:*:* |
|
Vendors & Products |
Cisco
Cisco network Services Orchestrator |
|
Metrics |
ssvc
|
Mon, 18 Nov 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data. This vulnerability exists because the web-management interface and certain HTTP-based APIs do not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. | |
Title | Cisco Network Services Orchestrator Path Traversal Vulnerability | |
Weaknesses | CWE-35 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2024-11-18T15:42:08.936Z
Updated: 2024-11-18T16:36:46.502Z
Reserved: 2020-11-13T00:00:00.000Z
Link: CVE-2021-1132
Vulnrichment
Updated: 2024-11-18T16:36:32.060Z
NVD
Status : Awaiting Analysis
Published: 2024-11-18T16:15:08.343
Modified: 2024-11-18T17:11:17.393
Link: CVE-2021-1132
Redhat
No data.