CVE-2014-3319
published 2014-07-14CVE-2014-3319: Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) allows remote authenticated…
PriorityP433medium6.8CVSS 2.0
AVNACLAuSCCINAN
EPSS
2.75%
84.7th percentile
Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup57676.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
vendor_redhat7.8HIGH
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Real-Time Monitoring Tool Path Traversal Vulnerability
vendor_cisco·2014-07-11·CVSS 6.8
CVE-2014-3319 [MEDIUM] CWE-22 Cisco Unified Communications Manager Real-Time Monitoring Tool Path Traversal Vulnerability
Cisco Unified Communications Manager Real-Time Monitoring Tool Path Traversal Vulnerability
A vulnerability in the Real-Time Monitoring Tool (RTMT) of Cisco Unified Communications Manager (Cisco Unified CM) could allow an authenticated, remote attacker to download files from arbitrary locations on the filesystem.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting crafted URL requests to a vulnerable device.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
Although an attacker must authenticate to an affected device to exploit this vulnerability, the attacker could persuade an authenticated user to click a malicious link by using misleading language and instruction
GHSA
GHSA-m8cw-q6xj-6rv6: Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-3319 [MEDIUM] CWE-22 GHSA-m8cw-q6xj-6rv6: Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10
Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup57676.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/59734http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3319http://tools.cisco.com/security/center/viewAlert.x?alertId=34909http://www.securitytracker.com/id/1030554https://exchange.xforce.ibmcloud.com/vulnerabilities/94436http://secunia.com/advisories/59734http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3319http://tools.cisco.com/security/center/viewAlert.x?alertId=34909http://www.securitytracker.com/id/1030554https://exchange.xforce.ibmcloud.com/vulnerabilities/94436
2014-07-14
Published