CVE-2013-5486

critical
Published 2013-09-23 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. NOTE: this can be leveraged to execute arbitrary commands by using the JBoss autodeploy functionality.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130918-dcnm

Application impact

VendorProductVersionsFixed
ciscoprime_data_center_network_manager4.1\(2\)
ciscoprime_data_center_network_manager4.1\(3\)
ciscoprime_data_center_network_manager4.1\(4\)
ciscoprime_data_center_network_manager4.1\(5\)
ciscoprime_data_center_network_manager4.2\(1\)
ciscoprime_data_center_network_manager4.2\(3\)
ciscoprime_data_center_network_manager5.0\(2\)
ciscoprime_data_center_network_manager5.0\(3\)
ciscoprime_data_center_network_manager5.1\(1\)
ciscoprime_data_center_network_manager5.1\(2\)
ciscoprime_data_center_network_manager5.1\(3u\)
ciscoprime_data_center_network_manager5.2\(2\)
ciscoprime_data_center_network_manager5.2\(2a\)
ciscoprime_data_center_network_manager5.2\(2b\)
ciscoprime_data_center_network_manager5.2\(2c\)
ciscoprime_data_center_network_manager5.2\(2e\)
ciscoprime_data_center_network_manager6.1\(1a\)
ciscoprime_data_center_network_manager6.1\(1b\)
ciscoprime_data_center_network_manager{"endIncluding":"6.1\\(1b\\)"}

References

CWEs

CWE-78

Verify integrity in audit chain (admin only). AS-IS.