A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to access sensitive data on an affected device.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-22 | |
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2024-03-06T16:33:48.826Z
Updated: 2024-11-05T18:06:40.528Z
Reserved: 2023-11-08T15:08:07.643Z
Link: CVE-2024-20345
Vulnrichment
Updated: 2024-08-01T21:59:41.830Z
NVD
Status : Awaiting Analysis
Published: 2024-03-06T17:15:09.973
Modified: 2024-11-05T18:35:04.167
Link: CVE-2024-20345
Redhat
No data.