← volver
CVE-2017-6629

CVE-2017-6629

EPSS 2.5%CWE-22
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 2.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
03 may 2017Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device. The issue is due to improper sanitization of user-supplied input in HTTP POST parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. Cisco Bug IDs: CSCvd90118.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →