7.8
CVSSv2

CVE-2013-5490

Published: 23/09/2013 Updated: 29/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Cisco Prime Data Center Network Manager (DCNM) prior to 6.2(1) allows remote malicious users to read arbitrary text files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCud80148.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime data center network manager 6.1\\(1a\\)

cisco prime data center network manager 5.2\\(2e\\)

cisco prime data center network manager

cisco prime data center network manager 5.2\\(2c\\)

cisco prime data center network manager 5.0\\(3\\)

cisco prime data center network manager 5.0\\(2\\)

cisco prime data center network manager 6.1\\(1b\\)

cisco prime data center network manager 5.1\\(2\\)

cisco prime data center network manager 5.1\\(1\\)

cisco prime data center network manager 4.1\\(3\\)

cisco prime data center network manager 4.1\\(2\\)

cisco prime data center network manager 5.2\\(2\\)

cisco prime data center network manager 5.1\\(3u\\)

cisco prime data center network manager 4.1\\(5\\)

cisco prime data center network manager 4.1\\(4\\)

cisco prime data center network manager 5.2\\(2b\\)

cisco prime data center network manager 5.2\\(2a\\)

cisco prime data center network manager 4.2\\(3\\)

cisco prime data center network manager 4.2\\(1\\)

Vendor Advisories

Cisco Prime Data Center Network Manager (DCNM) contains multiple vulnerabilities that could allow an unauthenticated, remote attacker to disclose file components, and access text files on an affected device Various components of Cisco Prime DCNM are affected These vulnerabilities can be exploited independently on the same device; however, a rele ...