CVE-2015-0666: Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 40.4% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

Affected products

  • Cisco Prime Data Center Network Manager: up to and including 7.0\(2\); version 6.3(1) only; version 6.3(2) only; version 7.0(1) only

Published 2015-04-03. Last modified 2026-06-17.