SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-1607

Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to…

MEDIUM 6.5EPSS 2.26%

Does this matter?

Lower severity and a low EPSS score (2.26%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary directories via a modified pathname in an upload request, aka Bug ID CSCti81603.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
2.26% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
cisco/unified communications manager
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.