Vulnerability Description
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ciscoworks Common Services | 3.0.3 |
| Cisco | Ciscoworks Health And Utilization Monitor | 1.0 |
| Cisco | Ciscoworks Lan Management Solution | 2.5 |
| Cisco | Ciscoworks Qos Policy Manager | 4.0 |
| Cisco | Ciscoworks Voice Manager | 3.0 |
| Cisco | Security Manager | 3.0 |
| Cisco | Telepresence Readiness Assessment Manager | 1.0 |
| Cisco | Unified Operations Manager | 1.0 |
| Cisco | Unified Provisioning Manager | 1.0 |
| Cisco | Unified Service Monitor | 1.0 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN62527913/index.html
- http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000032.html
- http://osvdb.org/54616
- http://secunia.com/advisories/35179
- http://securitytracker.com/id?1022263
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080ab7b56.sPatchVendor Advisory
- http://www.securityfocus.com/bid/35040
- http://www.vupen.com/english/advisories/2009/1390
- http://jvn.jp/en/jp/JVN62527913/index.html
- http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000032.html
- http://osvdb.org/54616
- http://secunia.com/advisories/35179
- http://securitytracker.com/id?1022263
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080ab7b56.sPatchVendor Advisory
- http://www.securityfocus.com/bid/35040
FAQ
What is CVE-2009-1161?
CVE-2009-1161 is a vulnerability with a CVSS score of 10.0 (HIGH). Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresenc...
How severe is CVE-2009-1161?
CVE-2009-1161 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1161?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ciscoworks Common Services, Cisco Ciscoworks Health And Utilization Monitor, Cisco Ciscoworks Lan Management Solution, Cisco Ciscoworks Qos Policy Manager, Cisco Ciscoworks Voice Manager.