CVE-2015-0680
published 2015-03-28CVE-2015-0680: Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files…
PriorityP424medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.32%
67.6th percentile
Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wwm-mg8q-ph4g: Cisco Unified Call Manager (CM) 9
ghsa_unreviewed·2022-05-17
CVE-2015-0680 [MEDIUM] CWE-200 GHSA-9wwm-mg8q-ph4g: Cisco Unified Call Manager (CM) 9
Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439.
Cisco
Cisco Unified Call Manager Arbitrary File Retrieval Vulnerability
vendor_cisco·2015-03-27·CVSS 4.0
CVE-2015-0680 [MEDIUM] CWE-264 Cisco Unified Call Manager Arbitrary File Retrieval Vulnerability
Cisco Unified Call Manager Arbitrary File Retrieval Vulnerability
A vulnerability in Cisco Unified Call Manager (Cisco Unified CM) could allow an authenticated, remote attacker to retrieve arbitrary files.
The vulnerability is due to improper security restrictions by the affected application while handling requests for resources. An authenticated, remote attacker could exploit this vulnerability to retrieve arbitrary files from a targeted device. A successful exploit could be used to conduct further attacks.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit.
There are known fixed releases that m
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-03-28
Published