CVE-2009-1161
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 12.55% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cisco/ciscoworks common services · cisco/ciscoworks health and utilization monitor · cisco/ciscoworks lan management solution · cisco/ciscoworks qos policy manager · cisco/ciscoworks voice manager · cisco/security manager · cisco/telepresence readiness assessment manager · cisco/unified operations manager · cisco/unified provisioning manager · cisco/unified service monitor
- Source
- psirt@cisco.com
References
- http://jvn.jp/en/jp/JVN62527913/index.html
- http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000032.html
- http://osvdb.org/54616
- http://secunia.com/advisories/35179
- http://securitytracker.com/id?1022263
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080ab7b56.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35040
- http://www.vupen.com/english/advisories/2009/1390
- http://jvn.jp/en/jp/JVN62527913/index.html
- http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000032.html
- http://osvdb.org/54616
- http://secunia.com/advisories/35179
- http://securitytracker.com/id?1022263
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080ab7b56.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35040
- http://www.vupen.com/english/advisories/2009/1390
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.