CVE-2015-6407
published 2015-12-13CVE-2015-6407: Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.
PriorityP428medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.62%
73.6th percentile
Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | emergency_responder | — | — |
| cisco | emergency_responder_web_framework | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Emergency Responder Web Framework Arbitrary File Upload Vulnerability
vendor_cisco·2015-12-10·CVSS 4.0
CVE-2015-6407 [MEDIUM] CWE-20 Cisco Emergency Responder Web Framework Arbitrary File Upload Vulnerability
Cisco Emergency Responder Web Framework Arbitrary File Upload Vulnerability
A vulnerability in the web framework of Cisco Emergency Responder (CER) could allow an unauthenticated, remote attacker to upload arbitrary files to a restricted location on the filesystem.
The vulnerability is due to insufficient parameter validation. An attacker could exploit this vulnerability by sending a crafted request to the server. An exploit could allow the attacker to upload arbitrary files to arbitrary locations on an affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151
Cisco
Cisco Emergency Responder Web Framework Arbitrary File Upload Vulnerability
vendor_cisco
CVE-2015-6407 Cisco Emergency Responder Web Framework Arbitrary File Upload Vulnerability
CVE-2015-6407: Cisco Emergency Responder Web Framework Arbitrary File Upload Vulnerability
A vulnerability in the web framework of Cisco Emergency Responder (CER) could allow an unauthenticated, remote attacker to upload arbitrary files to a restricted location on the filesystem. The vulnerability is due to insufficient parameter validation. An attacker could exploit this vulnerability by sending a crafted request to the server. An exploit could allow the attacker to upload arbitrary files to arbitrary locations on an affected device. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCuv25501
GHSA
GHSA-h7r4-jcmg-97wh: Cisco Emergency Responder 10
ghsa_unreviewed·2022-05-17
CVE-2015-6407 [MEDIUM] CWE-20 GHSA-h7r4-jcmg-97wh: Cisco Emergency Responder 10
Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-erwhttp://www.securityfocus.com/bid/78817http://www.securitytracker.com/id/1034383http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-erwhttp://www.securityfocus.com/bid/78817http://www.securitytracker.com/id/1034383
2015-12-13
Published