CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:C/I:N/A:N
AI Score
Confidence
Low
EPSS
Percentile
98.6%
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | unified_ip_interactive_voice_response | - | cpe:2.3:h:cisco:unified_ip_interactive_voice_response:-:*:*:*:*:*:*:* |
cisco | unified_ip_ivr | 6.0(1) | cpe:2.3:a:cisco:unified_ip_ivr:6.0\(1\):*:*:*:*:*:*:* |
cisco | unified_ip_ivr | 7.0(1) | cpe:2.3:a:cisco:unified_ip_ivr:7.0\(1\):*:*:*:*:*:*:* |
cisco | unified_ip_ivr | 7.0(2) | cpe:2.3:a:cisco:unified_ip_ivr:7.0\(2\):*:*:*:*:*:*:* |
cisco | unified_ip_ivr | 8.0(1) | cpe:2.3:a:cisco:unified_ip_ivr:8.0\(1\):*:*:*:*:*:*:* |
cisco | unified_ip_ivr | 8.0(2) | cpe:2.3:a:cisco:unified_ip_ivr:8.0\(2\):*:*:*:*:*:*:* |
cisco | unified_ip_ivr | 8.5(1) | cpe:2.3:a:cisco:unified_ip_ivr:8.5\(1\):*:*:*:*:*:*:* |
cisco | unified_ccx | 6.0(1) | cpe:2.3:a:cisco:unified_ccx:6.0\(1\):*:*:*:*:*:*:* |
cisco | unified_ccx | 7.0(1) | cpe:2.3:a:cisco:unified_ccx:7.0\(1\):*:*:*:*:*:*:* |
cisco | unified_ccx | 7.0(2) | cpe:2.3:a:cisco:unified_ccx:7.0\(2\):*:*:*:*:*:*:* |