PT-2009-3256 · Cisco · Cisco Application Control Engine (Ace) Device Manager+1

Publicado

2009-02-26

·

Atualizado

2009-03-03

·

CVE-2009-0615

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Application Networking Manager versions prior to 2.0 Cisco Application Control Engine (ACE) Device Manager versions prior to A3(2.1)
Description The issue allows remote authenticated users to read or modify arbitrary files due to invalid directory permissions.
Recommendations For Cisco Application Networking Manager versions prior to 2.0, update to version 2.0 or later. For Cisco Application Control Engine (ACE) Device Manager versions prior to A3(2.1), update to version A3(2.1) or later.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0615

Produtos afetados

Cisco Application Control Engine (Ace) Device Manager
Cisco Application Networking Manager