CVE-2013-6689
published 2013-11-18CVE-2013-6689: Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary…
PriorityP426medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.35%
27.8th percentile
Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID CSCui58229.
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 9.1\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q8qh-g793-c4pf: Cisco Unified Communications Manager (Unified CM) 9
ghsa_unreviewed·2022-05-17
CVE-2013-6689 [MEDIUM] CWE-20 GHSA-q8qh-g793-c4pf: Cisco Unified Communications Manager (Unified CM) 9
Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID CSCui58229.
Cisco
Cisco Unified Communications Manager Arbitrary File Read/Write Vulnerability
vendor_cisco·2013-11-13·CVSS 6.9
CVE-2013-6689 [MEDIUM] CWE-20 Cisco Unified Communications Manager Arbitrary File Read/Write Vulnerability
Cisco Unified Communications Manager Arbitrary File Read/Write Vulnerability
A vulnerability in a command-line utility of Cisco Unified Communications Manager (Cisco Unified CM) could allow an authenticated, local attacker to read or write data to arbitrary locations on the filesystem.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by overloading the command-line utility. An exploit could allow the attacker to read or write files in arbitrary locations on the filesystem.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker would need local access to the targeted device, which decreases the likelihood of a successful exploit.
Cisco indicates through
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-18
Published