Vulnerability Intelligence Report
Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
CVE-2015-0666
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:40.61%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| cisco | prime_data_center_network_manager | 6.3\(1\), 6.3\(2\), 7.0\(1\) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cisco Systems, Inc. · Hosted Service · USA |
| Reserved | 2015-01-07T00:00:00 |
| Published | 2015-04-03T10:00:00 |
| Patch Date | 2015-04-01 |
| Last Updated | 2026-01-12T20:44:11 |
Community Chatter & Buzz