CVE-2017-6629
CVE-2017-6629
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 2.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
03 may 2017Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device. The issue is due to improper sanitization of user-supplied input in HTTP POST parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. Cisco Bug IDs: CSCvd90118.
Productos afectados
n/a · Cisco Unity Connection¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →