CVE-2011-3305

Cisco Nac Manager - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in Cisco Network Admission Control (NAC) Manager 4.8.x allows remote attackers to read arbitrary files via crafted traffic to TCP port 443, aka Bug ID CSCtq10755.

Exploits (1)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/cisco_nac_manager_traversal.rb

Scores

EPSS 0.4200
EPSS Percentile 97.4%

Details

CWE
CWE-22
Status published
Products (3)
cisco/nac_manager 4.8
cisco/nac_manager 4.8\(1\)
cisco/nac_manager 4.8\(2\)
Published Oct 06, 2011
Tracked Since Feb 18, 2026