HIGH · 7.8

CVE-2011-3315

Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (a...

Vulnerability Description

Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoUnified Ip Interactive Voice Response-
CiscoUnified Ip Ivr6.0\(1\)
CiscoUnified Ccx6.0\(1\)
CiscoUnified Communications Manager5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-3315?

CVE-2011-3315 is a vulnerability with a CVSS score of 7.8 (HIGH). Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (a...

How severe is CVE-2011-3315?

CVE-2011-3315 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-3315?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Ip Interactive Voice Response, Cisco Unified Ip Ivr, Cisco Unified Ccx, Cisco Unified Communications Manager.