Lucene search

K
cveCiscoCVE-2011-3315
HistoryOct 27, 2011 - 9:55 p.m.

CVE-2011-3315

2011-10-2721:55:00
CWE-22
cisco
web.nvd.nist.gov
25
cisco
unified communications manager
cucm
vulnerability
cve-2011-3315
directory traversal
security advisory

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.851

Percentile

98.6%

Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.

Affected configurations

Nvd
Node
ciscounified_ip_interactive_voice_responseMatch-
AND
ciscounified_ip_ivrMatch6.0\(1\)
OR
ciscounified_ip_ivrMatch7.0\(1\)
OR
ciscounified_ip_ivrMatch7.0\(2\)
OR
ciscounified_ip_ivrMatch8.0\(1\)
OR
ciscounified_ip_ivrMatch8.0\(2\)
OR
ciscounified_ip_ivrMatch8.5\(1\)
Node
ciscounified_ccxMatch6.0\(1\)
OR
ciscounified_ccxMatch7.0\(1\)
OR
ciscounified_ccxMatch7.0\(2\)
OR
ciscounified_ccxMatch8.0\(1\)
OR
ciscounified_ccxMatch8.0\(2\)
OR
ciscounified_ccxMatch8.5\(1\)
OR
ciscounified_communications_managerMatch5.0
OR
ciscounified_communications_managerMatch5.1
OR
ciscounified_communications_managerMatch5.1\(1\)
OR
ciscounified_communications_managerMatch5.1\(1b\)
OR
ciscounified_communications_managerMatch5.1\(1c\)
OR
ciscounified_communications_managerMatch5.1\(2\)
OR
ciscounified_communications_managerMatch5.1\(2a\)
OR
ciscounified_communications_managerMatch5.1\(2b\)
OR
ciscounified_communications_managerMatch5.1\(3\)
OR
ciscounified_communications_managerMatch5.1\(3a\)
OR
ciscounified_communications_managerMatch5.1\(3c\)
OR
ciscounified_communications_managerMatch5.1\(3d\)
OR
ciscounified_communications_managerMatch5.1\(3e\)
OR
ciscounified_communications_managerMatch5.1.2
OR
ciscounified_communications_managerMatch6.0
OR
ciscounified_communications_managerMatch6.1\(1\)
OR
ciscounified_communications_managerMatch6.1\(1a\)
OR
ciscounified_communications_managerMatch6.1\(1b\)
OR
ciscounified_communications_managerMatch6.1\(2\)
OR
ciscounified_communications_managerMatch6.1\(2\)su1
OR
ciscounified_communications_managerMatch6.1\(2\)su1a
OR
ciscounified_communications_managerMatch6.1\(3\)
OR
ciscounified_communications_managerMatch6.1\(3a\)
OR
ciscounified_communications_managerMatch6.1\(3b\)
OR
ciscounified_communications_managerMatch6.1\(3b\)su1
OR
ciscounified_communications_managerMatch6.1\(4\)
OR
ciscounified_communications_managerMatch6.1\(4\)su1
OR
ciscounified_communications_managerMatch6.1\(4a\)
OR
ciscounified_communications_managerMatch6.1\(4a\)su2
OR
ciscounified_communications_managerMatch6.1\(5\)
OR
ciscounified_communications_managerMatch6.1\(5\)su1
OR
ciscounified_communications_managerMatch7.0\(1\)su1
OR
ciscounified_communications_managerMatch7.0\(1\)su1a
OR
ciscounified_communications_managerMatch7.0\(2\)
OR
ciscounified_communications_managerMatch7.0\(2a\)
OR
ciscounified_communications_managerMatch7.0\(2a\)su1
OR
ciscounified_communications_managerMatch7.0\(2a\)su2
OR
ciscounified_communications_managerMatch7.1\(2a\)
OR
ciscounified_communications_managerMatch7.1\(2a\)su1
OR
ciscounified_communications_managerMatch7.1\(2b\)
OR
ciscounified_communications_managerMatch7.1\(2b\)su1
OR
ciscounified_communications_managerMatch7.1\(3\)
OR
ciscounified_communications_managerMatch7.1\(3a\)
OR
ciscounified_communications_managerMatch7.1\(3a\)su1
OR
ciscounified_communications_managerMatch7.1\(3a\)su1a
OR
ciscounified_communications_managerMatch7.1\(3b\)
OR
ciscounified_communications_managerMatch7.1\(3b\)su1
OR
ciscounified_communications_managerMatch7.1\(3b\)su2
OR
ciscounified_communications_managerMatch7.1\(5\)
OR
ciscounified_communications_managerMatch7.1\(5\)su1
OR
ciscounified_communications_managerMatch7.1\(5\)su1a
OR
ciscounified_communications_managerMatch7.1\(5a\)
OR
ciscounified_communications_managerMatch7.1\(5b\)
OR
ciscounified_communications_managerMatch7.1\(5b\)su1
OR
ciscounified_communications_managerMatch7.1\(5b\)su1a
OR
ciscounified_communications_managerMatch8.0
OR
ciscounified_communications_managerMatch8.0\(1\)
OR
ciscounified_communications_managerMatch8.0\(2\)
OR
ciscounified_communications_managerMatch8.0\(2a\)
OR
ciscounified_communications_managerMatch8.0\(2b\)
OR
ciscounified_communications_managerMatch8.0\(2c\)
OR
ciscounified_communications_managerMatch8.0\(2c\)su1
VendorProductVersionCPE
ciscounified_ip_interactive_voice_response-cpe:2.3:h:cisco:unified_ip_interactive_voice_response:-:*:*:*:*:*:*:*
ciscounified_ip_ivr6.0(1)cpe:2.3:a:cisco:unified_ip_ivr:6.0\(1\):*:*:*:*:*:*:*
ciscounified_ip_ivr7.0(1)cpe:2.3:a:cisco:unified_ip_ivr:7.0\(1\):*:*:*:*:*:*:*
ciscounified_ip_ivr7.0(2)cpe:2.3:a:cisco:unified_ip_ivr:7.0\(2\):*:*:*:*:*:*:*
ciscounified_ip_ivr8.0(1)cpe:2.3:a:cisco:unified_ip_ivr:8.0\(1\):*:*:*:*:*:*:*
ciscounified_ip_ivr8.0(2)cpe:2.3:a:cisco:unified_ip_ivr:8.0\(2\):*:*:*:*:*:*:*
ciscounified_ip_ivr8.5(1)cpe:2.3:a:cisco:unified_ip_ivr:8.5\(1\):*:*:*:*:*:*:*
ciscounified_ccx6.0(1)cpe:2.3:a:cisco:unified_ccx:6.0\(1\):*:*:*:*:*:*:*
ciscounified_ccx7.0(1)cpe:2.3:a:cisco:unified_ccx:7.0\(1\):*:*:*:*:*:*:*
ciscounified_ccx7.0(2)cpe:2.3:a:cisco:unified_ccx:7.0\(2\):*:*:*:*:*:*:*
Rows per page:
1-10 of 751

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.851

Percentile

98.6%