CVE-2011-3315
published 2011-10-27CVE-2011-3315: Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3)…
PriorityP277high7.8CVSS 2.0
AVNACLAuNCCINAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
26.39%
97.8th percentile
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/ccmivr/IVRGetAudioFile.do?file=../../../../../../../../../../../../../../../usr/local/platform/conf/platformConfig.xml↗
path/ccmivr/IVRGetAudioFile.do
- →Detect directory traversal attempts targeting the vulnerable endpoint by matching GET requests to /ccmivr/IVRGetAudioFile.do with a 'file' parameter containing '../' sequences ↗
- →A successful exploitation response will contain the contents of /etc/passwd; match on the regex pattern 'root:.*:0:0:' in HTTP 200 responses to the vulnerable endpoint
- →The vulnerability is exploitable by unauthenticated remote attackers via a crafted URL; no authentication header is required in the request ↗
- ·Affected products span multiple version lines; ensure version-scoped detection/blocking is applied to CUCM 5.x, 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), as well as UCCX/Unified IP-IVR before their respective fixed versions ↗
- ·Two separate Cisco Bug IDs track this vulnerability across different product lines (CSCth09343 for CUCM, CSCts44049 for UCCX/IP-IVR); both share the same vulnerable endpoint pattern ↗
- ·There are no workarounds available for this vulnerability; patching is the only mitigation ↗
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vulncheck7.8HIGH
vendor_cisco7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Contact Center Express Directory Traversal Vulnerability
vendor_cisco·2011-10-26·CVSS 7.8
CVE-2011-3315 [HIGH] Cisco Unified Contact Center Express Directory Traversal Vulnerability
Cisco Unified Contact Center Express Directory Traversal Vulnerability
Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) contain a directory traversal vulnerability that may allow a remote,
unauthenticated attacker to retrieve arbitrary files from the
filesystem.
Cisco has released software updates that address this vulnerability.
��
There are no workarounds that mitigate this vulnerability.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx.
Cisco Unified Communications Manager is also affected
by this vulnerability and a separate advisory has been published at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso
Cisco
Cisco Unified Communications Manager Directory Traversal Vulnerability
vendor_cisco·2011-10-26·CVSS 7.8
CVE-2011-3315 [HIGH] Cisco Unified Communications Manager Directory Traversal Vulnerability
Cisco Unified Communications Manager Directory Traversal Vulnerability
Cisco Unified Communications Manager contains a directory traversal
vulnerability that may allow an unauthenticated, remote attacker to
retrieve arbitrary files from the filesystem.
Cisco has released software updates that address this vulnerability.
There are no workarounds that mitigate this vulnerability.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucm.
Cisco Unified Contact Center Express and Cisco Unified IP Interactive Voice Response are also affected by this vulnerability, and a separate advisory has been published at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx.
Note: Ef
Cisco
Cisco Unified Communications Manager Directory Traversal Vulnerability
vendor_cisco
CVE-2011-3315 Cisco Unified Communications Manager Directory Traversal Vulnerability
CVE-2011-3315: Cisco Unified Communications Manager Directory Traversal Vulnerability
Cisco Unified Communications Manager contains a directory traversal vulnerability that may allow an unauthenticated, remote attacker to retrieve arbitrary files from the filesystem. Cisco has released software updates that address this vulnerability. There are no
Bug IDs: CSCth09343, CSCts44049, CSCth09343
GHSA
GHSA-j2hg-jg54-wqj3: Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5
ghsa_unreviewed·2022-05-17
CVE-2011-3315 [HIGH] CWE-22 GHSA-j2hg-jg54-wqj3: Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
VulnCheck
Cisco unified_ip_interactive_voice_response Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2011·CVSS 7.8
CVE-2011-3315 [HIGH] Cisco unified_ip_interactive_voice_response Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Cisco unified_ip_interactive_voice_response Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
Affected: Cisco unified_ip_interactive_voice_response
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation
No detection rules found.
Exploit-DB
Cisco - 'file' Directory Traversal
exploitdb·2011-10-26
CVE-2011-3315 Cisco - 'file' Directory Traversal
Cisco - 'file' Directory Traversal
---
source: https://www.securityfocus.com/bid/50372/info
Multiple Cisco products are prone to a directory-traversal vulnerability.
Exploiting this issue will allow an attacker to read arbitrary files from locations outside of the application's current directory. This could help the attacker launch further attacks.
This issue is tracked by Cisco BugID CSCts44049 and CSCth09343.
The following products are affected:
Cisco Unified IP Interactive Voice Response
Cisco Unified Contact Center Express
Cisco Unified Communications Manager
http://www.example.com/ccmivr/IVRGetAudioFile.do?file=../../../../../../../../../../../../../../../etc/passwd
http://www.example.com/ccmivr/IVRGetAudioFile.do?file=../../../../../../../../../../../../../../../usr/local/pl
Nuclei
Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal
nuclei·CVSS 7.8
CVE-2011-3315 [HIGH] Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal
Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal
A directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
Template:
id: CVE-2011-3315
info:
name: Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal
author: daffainfo
severity: high
description: A directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x b
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucmhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccxhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucmhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx
2011-10-27
Published
Exploited in the wild