CVE-2012-4135
published 2013-12-21CVE-2012-4135: Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments…
PriorityP422medium4.6CVSS 2.0
AVLACLAuSCNICAN
EPSS
0.47%
38.0th percentile
Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | <= 6.1\(2\) | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:S/C:N/I:C/A:N
vendor_cisco4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Directory Traversal Vulnerability
vendor_cisco·2013-12-19·CVSS 4.6
CVE-2012-4135 [MEDIUM] CWE-22 Cisco NX-OS Directory Traversal Vulnerability
Cisco NX-OS Directory Traversal Vulnerability
A vulnerability in the Command Line Interface (CLI) of the Cisco NX-OS Software could allow an authenticated, local attacker to delete arbitrary files on the device.
The vulnerability is due to improper filtering of user input. An attacker could exploit this vulnerability by leveraging the filesys delete command to perform a directory traversal attack. An exploit could allow the attacker to delete arbitrary files on an affected device.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must have local access to the targeted device. This access requirement decreases the likelihood of a successful exploit.
Cisco indicates through the CVSS score
GHSA
GHSA-3wjp-mcmp-h4xw: Directory traversal vulnerability in filesys in Cisco NX-OS 6
ghsa_unreviewed·2022-05-17
CVE-2012-4135 [MEDIUM] CWE-22 GHSA-3wjp-mcmp-h4xw: Directory traversal vulnerability in filesys in Cisco NX-OS 6
Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-12-21
Published