CVE-2015-6406
published 2015-12-13CVE-2015-6406: Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files…
PriorityP425medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
2.31%
81.5th percentile
Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | emergency_responder | — | — |
| cisco | emergency_responder_tools_menu_directory | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Emergency Responder Tools Menu Directory Traversal Vulnerability
vendor_cisco·2015-12-10·CVSS 4.0
CVE-2015-6406 [MEDIUM] CWE-22 Cisco Emergency Responder Tools Menu Directory Traversal Vulnerability
Cisco Emergency Responder Tools Menu Directory Traversal Vulnerability
A vulnerability in the Tools menu of Cisco Emergency Responder could allow an authenticated, remote attacker to put files in arbitrary locations on an affected device.
The vulnerability is due to a failure to properly sanitize user-supplied input that is provided to the Tools menu as part of a filename. An attacker could exploit this vulnerability by using directory traversal methods to supply a path to a desired file location.
Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-ert
Cisco
Cisco Emergency Responder Tools Menu Directory Traversal Vulnerability
vendor_cisco
CVE-2015-6406 Cisco Emergency Responder Tools Menu Directory Traversal Vulnerability
CVE-2015-6406: Cisco Emergency Responder Tools Menu Directory Traversal Vulnerability
A vulnerability in the Tools menu of Cisco Emergency Responder could allow an authenticated, remote attacker to put files in arbitrary locations on an affected device. The vulnerability is due to a failure to properly sanitize user-supplied input that is provided to the Tools menu as part of a filename. An attacker could exploit this vulnerability by using directory traversal methods to supply a path to a desired file location. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-22, CWE-22
Bug IDs: CSCuv21781
GHSA
GHSA-7xx8-4prf-jp47: Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10
ghsa_unreviewed·2022-05-17
CVE-2015-6406 [MEDIUM] CWE-22 GHSA-7xx8-4prf-jp47: Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10
Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-erthttp://www.securityfocus.com/bid/78816http://www.securitytracker.com/id/1034384http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-erthttp://www.securityfocus.com/bid/78816http://www.securitytracker.com/id/1034384
2015-12-13
Published