CVE-2014-2276 Information

Description

The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to the Connectrix Manager repository which allows remote attackers to obtain sensitive information by importing a crafted firmware file.

Reference

http://archives.neohapsis.com/archives/bugtraq/2014-03/0115.html http://secunia.com/advisories/57513 http://www.securityfocus.com/bid/66308 http://www.securitytracker.com/id/1029939 https://exchange.xforce.ibmcloud.com/vulnerabilities/91987

Share on: