Cisco Unified Contact Center Express Directory Traversal Vulnerability
5 Apr. 2012
Summary
Successful exploitation of the vulnerability may allow a remote, unauthenticated attacker to retrieve arbitrary files from the Cisco Unified Contact Center Express or Cisco Unified IP Interactive Voice Response filesystem.
.Vulnerable Systems:
*Cisco UCCX version 6.0(x)
*Cisco UCCX version 7.0(x)
*Cisco UCCX version 8.0(x)
*Cisco UCCX version 8.5(x)
*Cisco Unified IP Interactive Voice Response version 6.0(x)
*Cisco Unified IP Interactive Voice Response version 7.0(x)
*Cisco Unified IP Interactive Voice Response version 8.0(x)
*Cisco Unified IP Interactive Voice Response version 8.5(x)
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
Vendor Status:
Cisco has issued an update to correct this vulnerability