The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to the Connectrix Manager repository, which allows remote attackers to obtain sensitive information by importing a crafted firmware file.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1029939 | vdb entry |
http://secunia.com/advisories/57513 | third party advisory |
http://www.securityfocus.com/bid/66308 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/91987 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2014-03/0115.html | mailing list |