cbcvebase.
CVE-2011-3315
published 2011-10-27

CVE-2011-3315: Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3)…

PriorityP277high7.8CVSS 2.0
AVNACLAuNCCINAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
26.39%
97.8th percentile
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.

Affected

69 ranges· showing 25
VendorProductVersion rangeFixed in
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager

Detection & IOCsextracted from sources · hover to see the quote

url/ccmivr/IVRGetAudioFile.do?file=../../../../../../../../../../../../../../../etc/passwd
url/ccmivr/IVRGetAudioFile.do?file=../../../../../../../../../../../../../../../usr/local/platform/conf/platformConfig.xml
path/ccmivr/IVRGetAudioFile.do
  • Detect directory traversal attempts targeting the vulnerable endpoint by matching GET requests to /ccmivr/IVRGetAudioFile.do with a 'file' parameter containing '../' sequences
  • A successful exploitation response will contain the contents of /etc/passwd; match on the regex pattern 'root:.*:0:0:' in HTTP 200 responses to the vulnerable endpoint
  • The vulnerability is exploitable by unauthenticated remote attackers via a crafted URL; no authentication header is required in the request
  • ·Affected products span multiple version lines; ensure version-scoped detection/blocking is applied to CUCM 5.x, 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), as well as UCCX/Unified IP-IVR before their respective fixed versions
  • ·Two separate Cisco Bug IDs track this vulnerability across different product lines (CSCth09343 for CUCM, CSCts44049 for UCCX/IP-IVR); both share the same vulnerable endpoint pattern
  • ·There are no workarounds available for this vulnerability; patching is the only mitigation

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vulncheck7.8HIGH
vendor_cisco7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.