CVE-2016-9208
A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an…
Does this matter?
Lower severity and a low EPSS score (2.69%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected device. More Information: CSCva98951 CSCva98954 CSCvb57494. Known Affected Releases: 11.5(2.10000.5). Known Fixed Releases: 12.0(0.98000.14) 12.0(0.98000.16).
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.69% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cisco/emergency responder
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/94800Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037426Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-cer1Vendor Advisory
- http://www.securityfocus.com/bid/94800Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037426Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-cer1Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.