CVE-2010-1571
published 2010-06-10CVE-2010-1571: Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0…
PriorityP341high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
2.92%
85.5th percentile
Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | customer_response_solution | — | — |
| cisco | customer_response_solution | — | — |
| cisco | customer_response_solution | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_ip_interactive_voice_response | — | — |
| cisco | unified_ip_interactive_voice_response | — | — |
| cisco | unified_ip_interactive_voice_response | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vendor_redhat10.0CRITICAL
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Vulnerabilities in Cisco Unified Contact Center Express
vendor_cisco·2010-06-09·CVSS 7.8
CVE-2010-1569 [HIGH] CWE-22 Vulnerabilities in Cisco Unified Contact Center Express
Vulnerabilities in Cisco Unified Contact Center Express
Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a
denial of service (DoS) vulnerability and a directory traversal vulnerability.
These vulnerabilities are independent of each other.
Exploitation of these vulnerabilities could result in a DoS condition
or an information disclosure.
Cisco has released software updates that address these vulnerabilities in the latest versions of Cisco Unified Contact Center
products.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100609-uccx.
Red Hat
Mozilla incorrectly frees used memory (MFSA 2010-03)
vendor_redhat·2010-02-17·CVSS 10.0
CVE-2009-1571 [CRITICAL] Mozilla incorrectly frees used memory (MFSA 2010-03)
Mozilla incorrectly frees used memory (MFSA 2010-03)
Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
Cisco
Vulnerabilities in Cisco Unified Contact Center Express
vendor_cisco
CVE-2010-1571 Vulnerabilities in Cisco Unified Contact Center Express
CVE-2010-1571: Vulnerabilities in Cisco Unified Contact Center Express
Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities are independent of each other. Exploitation of these vulnerabilities could result in a DoS condition or an information disclosure. Cisco has released software updates that address these vulnerabilities in the latest versions of Cisco Unified Contact Center products. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100609-uccx .
CWE: CWE-22, CWE-399, CWE-22, CWE-399
Bug IDs: CSCso89629, CSCsx76165, CSCso89629, CSCsx76165
GHSA
GHSA-cmmh-79gj-wg2r: Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7
ghsa_unreviewed·2022-05-17
CVE-2010-1571 [HIGH] CWE-22 GHSA-cmmh-79gj-wg2r: Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7
Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2f110.shtmlhttp://www.securityfocus.com/bid/40680http://www.securitytracker.com/id?1024082https://exchange.xforce.ibmcloud.com/vulnerabilities/59277http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2f110.shtmlhttp://www.securityfocus.com/bid/40680http://www.securitytracker.com/id?1024082https://exchange.xforce.ibmcloud.com/vulnerabilities/59277
2010-06-10
Published