Vulnerability record · CVE-2015-0666 · published 3 April 2015
CVE-2015-0666: Cisco Prime DCNM fmserver servlet path traversal file read
Cisco · Prime Data Center Network Manager
The fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) is vulnerable to directory traversal, letting a remote attacker read arbitrary files by supplying a crafted pathname. Because DCNM is a management platform, exposed file contents can include configuration and credential material, making this a serious information-disclosure issue.
Description
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityKnown exploitation is confirmed by CISA KEV and the flaw allows unauthenticated remote file disclosure on a management platform, though impact is limited to confidentiality.
What it is
The fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) is vulnerable to directory traversal, letting a remote attacker read arbitrary files by supplying a crafted pathname. Because DCNM is a management platform, exposed file contents can include configuration and credential material, making this a serious information-disclosure issue.
Impact
An attacker gains read access to arbitrary files on the DCNM host, which can expose configuration data, credentials or other sensitive content. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network through the fmserver servlet; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the DCNM web interface can attempt the crafted pathname.
Exploitation
It is listed in CISA KEV with a 2022-03-25 addition date, indicating known exploitation in the wild, and EPSS gives a 30-day probability of about 0.40 (98.6th percentile). No ransomware campaign use is documented.
What to do
- Upgrade Cisco Prime DCNM to 7.1(1) or later per the Cisco advisory.
- If immediate upgrade is not possible, restrict network access to the DCNM web interface to trusted management networks only.
- Place DCNM behind a reverse proxy or WAF rule that blocks traversal sequences in request paths.
- Rotate any credentials or secrets that may have been stored in files readable on the DCNM host.
- Monitor Cisco advisories for further updates on this product line.
Detection
- Search web or proxy logs for requests to the fmserver servlet containing traversal sequences such as ../ or encoded variants.
- Alert on unusual file-read patterns or errors from the DCNM host that suggest path manipulation attempts.
- Review DCNM host file access logs for reads of sensitive files outside expected application paths.
- Correlate DCNM access logs with outbound connections from the DCNM server to unknown hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-0666 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150401-dcnm | Vendor Advisory |
| http://www.securitytracker.com/id/1032009 | Broken Link |
| http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150401-dcnm | Vendor Advisory |
| http://www.securitytracker.com/id/1032009 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-0666 | US Government Resource |
Track CVE-2015-0666 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0666), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.