Lucene search

K
cveCiscoCVE-2014-3317
HistoryJul 14, 2014 - 9:55 p.m.

CVE-2014-3317

2014-07-1421:55:05
CWE-22
cisco
web.nvd.nist.gov
23
cve-2014-3317
directory traversal
cisco
unified communications manager
dna component
bug id
cscup76314
nvd

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

70.9%

Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314.

Affected configurations

Nvd
Node
ciscounified_communications_managerMatch10.0\(1\)
VendorProductVersionCPE
ciscounified_communications_manager10.0(1)cpe:2.3:a:cisco:unified_communications_manager:10.0\(1\):*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

70.9%

Related for CVE-2014-3317