Lucene search

K
cve[email protected]CVE-2013-5534
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-5534

2022-10-0316:14:55
CWE-22
web.nvd.nist.gov
22
cisco
unity connection
directory traversal
remote authentication
jsp code
cve-2013-5534

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.9%

Directory traversal vulnerability in the attachment service in the Voice Message Web Service (aka VMWS or Cisco Unity Web Service) in Cisco Unity Connection allows remote authenticated users to create files, and consequently execute arbitrary JSP code, via a crafted pathname for a file that is not a valid audio file, aka Bug ID CSCuj22948.

Affected configurations

NVD
Node
ciscounity_connectionMatch-

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.9%

Related for CVE-2013-5534