CVE-2013-5490
high
CVSS v3
—
CVSS v2
7.8
VIR risk
7.8
Description
Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCud80148.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130918-dcnm
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | prime_data_center_network_manager | {"endIncluding":"6.1\\(1b\\)"} | |
| cisco | prime_data_center_network_manager | 5.2\(2e\) | |
| cisco | prime_data_center_network_manager | 6.1\(1a\) | |
| cisco | prime_data_center_network_manager | 4.1\(2\) | |
| cisco | prime_data_center_network_manager | 4.1\(3\) | |
| cisco | prime_data_center_network_manager | 4.1\(4\) | |
| cisco | prime_data_center_network_manager | 4.1\(5\) | |
| cisco | prime_data_center_network_manager | 4.2\(1\) | |
| cisco | prime_data_center_network_manager | 4.2\(3\) | |
| cisco | prime_data_center_network_manager | 5.0\(2\) | |
| cisco | prime_data_center_network_manager | 5.0\(3\) | |
| cisco | prime_data_center_network_manager | 5.1\(1\) | |
| cisco | prime_data_center_network_manager | 5.1\(2\) | |
| cisco | prime_data_center_network_manager | 5.1\(3u\) | |
| cisco | prime_data_center_network_manager | 5.2\(2\) | |
| cisco | prime_data_center_network_manager | 5.2\(2a\) | |
| cisco | prime_data_center_network_manager | 5.2\(2b\) | |
| cisco | prime_data_center_network_manager | 5.2\(2c\) | |
| cisco | prime_data_center_network_manager | 6.1\(1b\) | |
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130918-dcnm
- http://www.securityfocus.com/bid/62485
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87191
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130918-dcnm
- http://www.securityfocus.com/bid/62485
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87191
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.