VulnerabilityModified
CVE-2015-6352
Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID…
MEDIUM 4.3EPSS 1.82%
Does this matter?
Lower severity and a low EPSS score (1.82%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut67891.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.82% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/hosted collaboration solution · cisco/unified communications domain manager
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151027-ucdVendor Advisory
- http://www.securityfocus.com/bid/77341
- http://www.securitytracker.com/id/1034022
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151027-ucdVendor Advisory
- http://www.securityfocus.com/bid/77341
- http://www.securitytracker.com/id/1034022
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.