PT-2014-5211 · Cisco · Cisco Unified Communications Manager

Published

2014-07-14

·

Updated

2017-08-29

·

CVE-2014-3317

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager version 10.0(1)
Description A directory traversal issue in the Multiple Analyzer component of the Dialed Number Analyzer (DNA) allows remote authenticated users to delete arbitrary files by using a crafted URL.
Recommendations For Cisco Unified Communications Manager version 10.0(1), update to a version that fixes this issue to prevent remote authenticated users from deleting arbitrary files.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3317

Affected Products

Cisco Unified Communications Manager