CVE-2015-6407

Severity
4.0MEDIUM
EPSS
0.2%
top 58.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 13
Latest updateMay 17

Description

Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

NVDcisco/emergency_responder10.5\(3.10000.9\)

🔴Vulnerability Details

2
GHSA
GHSA-h7r4-jcmg-97wh: Cisco Emergency Responder 102022-05-17
CVEList
CVE-2015-6407: Cisco Emergency Responder 102015-12-13

📋Vendor Advisories

1
Cisco
Cisco Emergency Responder Web Framework Arbitrary File Upload Vulnerability2015-12-10
CVE-2015-6407 (MEDIUM CVSS 4) | Cisco Emergency Responder 10.5(3.10 | cvebase.io