Impact
The vulnerability results from allowing external input to influence file system paths in Cisco Crosswork Planning, falling under CWE-73. Based on the description, it is inferred that an attacker could manipulate file paths or submit arbitrary file system requests, potentially allowing unauthorized reading, writing, or deletion of files that should be protected, leading to data disclosure or integrity compromise.
Affected Systems
Affects Cisco Crosswork Planning products released by Cisco. No specific version numbers are disclosed in the advisory, so all installations should be evaluated until an updated version that includes the hardening release is deployed.
Risk and Exploitability
A CVSS score of 10 indicates a critical vulnerability. The advisory does not detail the attack vector, and it is inferred that remote exploitation may be possible based on the high score. No public exploits are known, and the vulnerability is not listed in CISA KEV. The EPSS score is <1%, suggesting a very low probability of exploitation, although it is not zero.
OpenCVE Enrichment