Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Contact Center Express Directory Traversal Vulnerability

cisco-sa-20111026-uccx · High · Published · Updated

Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) contain a directory traversal vulnerability that may allow a remote, unauthenticated attacker to retrieve arbitrary files from the filesystem. Cisco has released software updates that address this vulnerability. �� There are no workarounds that mitigate this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx. Cisco Unified Communications Manager is also affected by this vulnerability and a separate advisory has been published at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucm. Note:��Effective October 18, 2011, Cisco moved the current list of Cisco Security Advisories and Responses published by Cisco PSIRT. The new location is https://sec.cloudapps.cisco.com/security/center/publicationListing. You can also navigate to this page from the Cisco Products and Services menu of the Cisco Security (SIO) Portal. Following this transition, new Cisco Security Advisories and Responses will be published to the new location. Although the URL has changed, the content of security documents and the vulnerability policy are not impacted. Cisco will continue to disclose security vulnerabilities in accordance with the published Security Vulnerability Policy. ��

Workarounds

No workaround information imported yet.

CVEsCVE-2011-3315
Cisco Bug IDsCSCth09343, CSCts44049
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:C/I:N/A:N/E:F/RL:OF/RC:C
Product Names From Source
Cisco Unified Communications Manager, Cisco Unified Contact Center Express, Cisco Unified IP Interactive Voice Response

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2011-3315 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2011-3315 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2011-3315 Cisco OpenVuln
Cisco Application Centric Infrastructure Virtual Edge CVE-2011-3315 Cisco OpenVuln
Cisco Unified IP Interactive Voice Response CVE-2011-3315 Cisco OpenVuln
Cisco Unified Contact Center Express CVE-2011-3315 Cisco OpenVuln
Cisco Unified Contact Center CVE-2011-3315 Cisco OpenVuln
Cisco Unified Communications Manager CVE-2011-3315 Cisco OpenVuln