Vulnerability record · CVE-2018-0258 · published 2 May 2018
CVE-2018-0258: Cisco Prime file upload servlet path traversal and arbitrary file execution
Cisco · Prime Data Center Network Manager
The Cisco Prime File Upload servlet in Cisco Prime Data Center Network Manager (10.0 and later) and Cisco Prime Infrastructure (all versions) allows a remote attacker to upload arbitrary files to any directory via path traversal and then execute them. The flaw combines CWE-22 path traversal with CWE-434 unrestricted file upload, and the CVSS 3.0 base score is 9.8 (critical). Because the affected products are management platforms, compromise can expose the systems and credentials they administer.
Description
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network Manager (DCNM) Version 10.0 and later, and Cisco Prime Infrastructure (PI) All versions. Cisco Bug IDs: CSCvf32411, CSCvf81727.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, combined with a high EPSS score, makes this a top-priority patch for any exposed Prime deployment.
What it is
The Cisco Prime File Upload servlet in Cisco Prime Data Center Network Manager (10.0 and later) and Cisco Prime Infrastructure (all versions) allows a remote attacker to upload arbitrary files to any directory via path traversal and then execute them. The flaw combines CWE-22 path traversal with CWE-434 unrestricted file upload, and the CVSS 3.0 base score is 9.8 (critical). Because the affected products are management platforms, compromise can expose the systems and credentials they administer.
Impact
An unauthenticated remote attacker can write files anywhere on the vulnerable device and execute them, gaining code execution with the privileges of the affected service. That can lead to full compromise of the Prime host and any managed infrastructure it controls.
Attack surface
The vulnerability is reached over the network through the Prime File Upload servlet, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. Any network-reachable Prime DCNM 10.0+ or Prime Infrastructure instance is exposed.
Exploitation
The record does not state that exploitation has been observed; CISA KEV does not list this CVE, but EPSS is high at 0.482 (98.8th percentile), indicating elevated likelihood of attempted exploitation. References are vendor and third-party advisories only, with no public exploit tag.
What to do
- Apply the Cisco security advisory cisco-sa-20180502-prime-upload fixes for Prime DCNM and Prime Infrastructure; patch is the first action.
- If patching cannot be done immediately, restrict network access to the Prime management interface to trusted administrative networks only.
- Do not expose Prime DCNM or Prime Infrastructure directly to the internet; place it behind a VPN or jump host.
- Review and harden file upload handling and directory permissions on Prime hosts, and monitor for unexpected files in web-accessible directories.
- Rotate credentials and secrets stored or managed by the Prime platform if compromise is suspected.
Detection
- Monitor Prime web server and servlet logs for file upload requests containing path traversal sequences such as ../ or encoded variants.
- Alert on new or modified executable files appearing in web-accessible or unexpected directories on Prime hosts.
- Watch for unexpected outbound connections or process execution from the Prime application service account.
- Correlate file upload activity with subsequent process creation on the Prime host to catch upload-then-execute chains.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104074 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180502-prime-upload | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2018-11 | Third Party Advisory |
| http://www.securityfocus.com/bid/104074 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180502-prime-upload | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2018-11 | Third Party Advisory |
Track CVE-2018-0258 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0258), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.