CVE-2013-1225
published 2013-05-09CVE-2013-1225: Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2)…
PriorityP340high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
1.59%
72.9th percentile
Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_customer_voice_portal | <= 9.0\(1\) | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
vendor_cisco·2013-05-08·CVSS 10.0
CVE-2013-1220 [CRITICAL] CWE-119 Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "Details" section for more information on the vulnerabilities. These vulnerabilities can be exploited independently; however, more than one vulnerability could be exploited on the same device.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp
Cisco
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
vendor_cisco
CVE-2013-1225 Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
CVE-2013-1225: Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "
CWE: CWE-119, CWE-16, CWE-200, CWE-119, CWE-16, CWE-200, CWE-22, CWE-119, CWE-16, CWE-200, CWE-119, CWE-16, CWE-200, CWE-22
Bug IDs: CSCua65148, CSCub38366, CSCub38369, CSCua65148, CSCub38366
GHSA
GHSA-qrch-6rw3-5j2h: Cisco Unified Customer Voice Portal (CVP) Software before 9
ghsa_unreviewed·2022-05-17
CVE-2013-1225 [HIGH] GHSA-qrch-6rw3-5j2h: Cisco Unified Customer Voice Portal (CVP) Software before 9
Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-05-09
Published