Vulnerability record · CVE-2013-2068 · published 28 September 2013
CVE-2013-2068: Red Hat CloudForms Management Engine AgentController path traversal
Redhat · Cloudforms Management Engine
The AgentController in Red Hat CloudForms Management Engine 2.0 contains multiple directory traversal flaws in its log, upload, and linuxpkgs methods. A remote attacker can supply a .. sequence in the filename parameter to write files outside the intended directory. Because arbitrary file creation and overwrite is possible, the flaw is serious for any exposed management engine.
Description
Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.
AV:N/AC:L/Au:N/C:N/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote arbitrary file write with a public exploit and very high EPSS score makes this an urgent fix despite the absence of KEV listing.
What it is
The AgentController in Red Hat CloudForms Management Engine 2.0 contains multiple directory traversal flaws in its log, upload, and linuxpkgs methods. A remote attacker can supply a .. sequence in the filename parameter to write files outside the intended directory. Because arbitrary file creation and overwrite is possible, the flaw is serious for any exposed management engine.
Impact
An attacker can create or overwrite arbitrary files on the server, which can lead to code execution or service disruption depending on what files are targeted. Integrity and availability are fully impacted; confidentiality is not.
Attack surface
Reachable over the network through the AgentController HTTP interface with no authentication required per the CVSS vector (AV:N/AC:L/Au:N). No user interaction is indicated.
Exploitation
Not listed in CISA KEV, but EPSS is 0.586 (99th percentile) and a public Exploit-DB entry (30469) exists, indicating exploit code is available and exploitation is plausible.
What to do
- Apply the Red Hat vendor advisory RHSA-2013-1206 fix for CloudForms Management Engine 2.0.
- Restrict network access to the AgentController interface to trusted management networks only.
- Validate and canonicalize the filename parameter, rejecting any path traversal sequences.
- Run the management engine with least privilege so file writes cannot reach sensitive paths.
- Monitor for unexpected file creation or modification in application and system directories.
Detection
- Inspect HTTP requests to AgentController log, upload, and linuxpkgs methods for .. sequences or absolute paths in the filename parameter.
- Alert on file creation or modification events in directories outside expected upload or log paths.
- Review web server and application logs for anomalous POST requests to AgentController endpoints from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2068 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2068), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.