A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to access sensitive data on an affected device.
History

Tue, 05 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-03-06T16:33:48.826Z

Updated: 2024-11-05T18:06:40.528Z

Reserved: 2023-11-08T15:08:07.643Z

Link: CVE-2024-20345

cve-icon Vulnrichment

Updated: 2024-08-01T21:59:41.830Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-06T17:15:09.973

Modified: 2024-11-05T18:35:04.167

Link: CVE-2024-20345

cve-icon Redhat

No data.