CVE-2021-34701
published 2021-11-04CVE-2021-34701: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session…
medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to access sensitive data on an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unity_connection | — | — |
| cisco | unified_communications_manager | < 14su1 | 14su1 |
| cisco | unified_communications_manager_im_and_presence_service | < 14su1 | 14su1 |
| cisco | unified_communications_products_path | — | — |
| cisco | unity_connection | < 14su1 | 14su1 |