CVE-2015-6352
published 2015-10-30CVE-2015-6352: Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.82%
76.2th percentile
Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut67891.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | hosted_collaboration_solution | — | — |
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager_uri_enumeration | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g6vr-9cmw-9pwh: Cisco Unified Communications Domain Manager before 10
ghsa_unreviewed·2022-05-17
CVE-2015-6352 [MEDIUM] CWE-200 GHSA-g6vr-9cmw-9pwh: Cisco Unified Communications Domain Manager before 10
Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut67891.
Cisco
Cisco Unified Communications Domain Manager URI Enumeration Vulnerability
vendor_cisco·2015-10-28·CVSS 4.3
CVE-2015-6352 [MEDIUM] CWE-200 Cisco Unified Communications Domain Manager URI Enumeration Vulnerability
Cisco Unified Communications Domain Manager URI Enumeration Vulnerability
A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to map a file system structure.
The vulnerability is due to different handling of existent and nonexistent paths. An attacker could exploit this vulnerability by enumerating all possible URIs and gathering the answers that the server gives to those paths. A successful exploit could allow the attacker to determine the file system structure and which URIs are valid resources.
Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content
Cisco
Cisco Unified Communications Domain Manager URI Enumeration Vulnerability
vendor_cisco
CVE-2015-6352 Cisco Unified Communications Domain Manager URI Enumeration Vulnerability
CVE-2015-6352: Cisco Unified Communications Domain Manager URI Enumeration Vulnerability
A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to map a file system structure. The vulnerability is due to different handling of existent and nonexistent paths. An attacker could exploit this vulnerability by enumerating all possible URIs and gathering the answers that the server gives to those paths. A successful exploit could allow the attacker to determine the file system structure and which URIs are valid resources. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCut67891
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151027-ucdhttp://www.securityfocus.com/bid/77341http://www.securitytracker.com/id/1034022http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151027-ucdhttp://www.securityfocus.com/bid/77341http://www.securitytracker.com/id/1034022
2015-10-30
Published