cisco-sa-catc-file-read-wLH2vf8X

Cisco Catalyst Center Arbitrary File Read Vulnerability

High · Updated · Cisco

1 product with CSAF evidence

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.