HIGH · 10.0

CVE-2009-1161

Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresenc...

Vulnerability Description

Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoCiscoworks Common Services3.0.3
CiscoCiscoworks Health And Utilization Monitor1.0
CiscoCiscoworks Lan Management Solution2.5
CiscoCiscoworks Qos Policy Manager4.0
CiscoCiscoworks Voice Manager3.0
CiscoSecurity Manager3.0
CiscoTelepresence Readiness Assessment Manager1.0
CiscoUnified Operations Manager1.0
CiscoUnified Provisioning Manager1.0
CiscoUnified Service Monitor1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-1161?

CVE-2009-1161 is a vulnerability with a CVSS score of 10.0 (HIGH). Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresenc...

How severe is CVE-2009-1161?

CVE-2009-1161 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-1161?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ciscoworks Common Services, Cisco Ciscoworks Health And Utilization Monitor, Cisco Ciscoworks Lan Management Solution, Cisco Ciscoworks Qos Policy Manager, Cisco Ciscoworks Voice Manager.