← Vulnerability feed

Vulnerability record · CVE-2018-0258 · published 2 May 2018

CVE-2018-0258: Cisco Prime file upload servlet path traversal and arbitrary file execution

Cisco · Prime Data Center Network Manager

The Cisco Prime File Upload servlet in Cisco Prime Data Center Network Manager (10.0 and later) and Cisco Prime Infrastructure (all versions) allows a remote attacker to upload arbitrary files to any directory via path traversal and then execute them. The flaw combines CWE-22 path traversal with CWE-434 unrestricted file upload, and the CVSS 3.0 base score is 9.8 (critical). Because the affected products are management platforms, compromise can expose the systems and credentials they administer.

9.8 CVSS 3.0 Critical EPSS 48% · top 1.2% CWE-22 · Path traversalCWE-434 · Unrestricted file upload
9.8CVSS 3.0 base score, v2 10.0
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network Manager (DCNM) Version 10.0 and later, and Cisco Prime Infrastructure (PI) All versions. Cisco Bug IDs: CSCvf32411, CSCvf81727.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, combined with a high EPSS score, makes this a top-priority patch for any exposed Prime deployment.

What it is

The Cisco Prime File Upload servlet in Cisco Prime Data Center Network Manager (10.0 and later) and Cisco Prime Infrastructure (all versions) allows a remote attacker to upload arbitrary files to any directory via path traversal and then execute them. The flaw combines CWE-22 path traversal with CWE-434 unrestricted file upload, and the CVSS 3.0 base score is 9.8 (critical). Because the affected products are management platforms, compromise can expose the systems and credentials they administer.

Impact

An unauthenticated remote attacker can write files anywhere on the vulnerable device and execute them, gaining code execution with the privileges of the affected service. That can lead to full compromise of the Prime host and any managed infrastructure it controls.

Attack surface

The vulnerability is reached over the network through the Prime File Upload servlet, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. Any network-reachable Prime DCNM 10.0+ or Prime Infrastructure instance is exposed.

Exploitation

The record does not state that exploitation has been observed; CISA KEV does not list this CVE, but EPSS is high at 0.482 (98.8th percentile), indicating elevated likelihood of attempted exploitation. References are vendor and third-party advisories only, with no public exploit tag.

What to do

  • Apply the Cisco security advisory cisco-sa-20180502-prime-upload fixes for Prime DCNM and Prime Infrastructure; patch is the first action.
  • If patching cannot be done immediately, restrict network access to the Prime management interface to trusted administrative networks only.
  • Do not expose Prime DCNM or Prime Infrastructure directly to the internet; place it behind a VPN or jump host.
  • Review and harden file upload handling and directory permissions on Prime hosts, and monitor for unexpected files in web-accessible directories.
  • Rotate credentials and secrets stored or managed by the Prime platform if compromise is suspected.

Detection

  • Monitor Prime web server and servlet logs for file upload requests containing path traversal sequences such as ../ or encoded variants.
  • Alert on new or modified executable files appearing in web-accessible or unexpected directories on Prime hosts.
  • Watch for unexpected outbound connections or process execution from the Prime application service account.
  • Correlate file upload activity with subsequent process creation on the Prime host to catch upload-then-execute chains.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0258 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2015-0666Cisco Prime DCNM fmserver servlet path traversal file readThe fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) is vulnerable to directory traversal, letting a remote attacker …KEVEPSS 40%analysed10.0CVE-2013-5486Cisco Prime DCNM path traversal in processImageSave.jsp enables file writeCisco Prime Data Center Network Manager (DCNM) before 6.2(1) contains a directory traversal flaw in processImageSave.jsp where the chartid parameter …EPSS 76%analysed10.0CVE-2012-5417Cisco prime data center network manager permissions and access controls vulnerabilityCisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which all…EPSS 3.1%9.8CVE-2019-15958Cisco prime infrastructure improper input validation vulnerabilityA vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticat…EPSS 3.3%9.8CVE-2019-1821Cisco Prime Infrastructure and EPN Manager input validation RCECisco Prime Infrastructure and Evolved Programmable Network Manager fail to properly validate user-supplied input in the web-based management interfa…EPSS 98%analysed9.8CVE-2018-15379Cisco Prime Infrastructure web server directory permission flaw allows file uploadCisco Prime Infrastructure's HTTP web server has incorrect permission settings on important system directories, letting an unauthenticated remote att…EPSS 86%analysed9.8CVE-2017-6639Cisco prime data center network manager missing authorization vulnerabilityA vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticate…EPSS 35%

Source: NIST National Vulnerability Database (record CVE-2018-0258), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.