CVE-2015-0666
KEVmoderateDirectory Traversal in Cisco Prime Data Center Network Manager (DCNM)
CISA: Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
CVE-2015-0666 is a directory traversal flaw (CWE-22) in the fmserver servlet of Cisco Prime Data Center Network Manager (DCNM), a management platform for Cisco data-center networking equipment. A remote attacker can send crafted requests containing traversal sequences to the fmserver servlet, bypassing intended path restrictions. Successful exploitation lets the attacker read arbitrary files from the DCNM server, potentially exposing configuration data, credentials, or other sensitive material stored on the host. Organizations running affected Cisco Prime DCNM deployments are affected, particularly where the management interface or fmserver servlet is reachable from untrusted networks. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (2022-03-25), indicating confirmed in-the-wild exploitation, with a high EPSS of 40.4% for exploitation in the next 30 days, though ransomware use has not been confirmed.
What to do: Apply Cisco updates for Prime DCNM per the vendor's instructions, as required by CISA's KEV listing. Inventory your environment for DCNM installations and check whether the fmserver servlet is exposed to untrusted networks, restricting access to trusted management hosts if patching must be deferred. Because the flaw has been exploited in the wild, review DCNM server access logs for signs of path-traversal requests while remediation is underway.
| Cisco Prime Data Center Network Manager (DCNM) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
- Affected
- Cisco Prime Data Center Network Manager (DCNM)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Cisco
- Products
- Prime Data Center Network Manager (DCNM)
- Weakness
- CWE-22