Lucene search

K
ciscoCiscoCISCO-SA-20120511-CVE-2011-4232
HistoryMay 11, 2012 - 1:48 p.m.

Cisco Unified MeetingPlace Directory Enumeration Information Disclosure Vulnerability

2012-05-1113:48:40
tools.cisco.com
11

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

67.9%

Cisco Unified MeetingPlace software contains a vulnerability that could allow an unauthenticated, remote attacker to access sensitive information on a targeted system.

The vulnerability is due to an unspecified error in the affected software that could allow an attacker to enumerate existing folders via directory transversal sequences. An unauthenticated, remote attacker could exploit this vulnerability to access sensitive information on the system. The attacker could use this information to launch further attacks.

Cisco has confirmed this vulnerability and released software updates.

To exploit this vulnerability, an attacker would need to access trusted, internal networks. This access requirement decreases the likelihood of a successful exploit.

Affected configurations

Vulners
Node
ciscounified_meetingplaceMatchany
OR
ciscounified_meetingplaceMatchany
VendorProductVersionCPE
ciscounified_meetingplaceanycpe:2.3:a:cisco:unified_meetingplace:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

67.9%

Related for CISCO-SA-20120511-CVE-2011-4232