CVE-2021-34701

CWE-22Path Traversal4 documents4 sources
Severity
4.3MEDIUM
EPSS
0.1%
top 74.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 24

Description

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to access sensitive data on an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied i

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2pf4-5wvc-pjgh: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Sessi2022-05-24
CVEList
Cisco Unified Communications Products Path Traversal Vulnerability2021-11-04

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Products Path Traversal Vulnerability2021-11-03
CVE-2021-34701 (MEDIUM CVSS 4.3) | A vulnerability in the web-based ma | cvebase.io