Vulnerability Description
Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arbitrary directories via unspecified vectors, aka Bug ID CSCtw56009.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Small Business Srp520 Series Firmware | <= 1.01.24 |
| Cisco | Small Business Srp521W | All versions |
| Cisco | Small Business Srp526W | All versions |
| Cisco | Small Business Srp527W | All versions |
| Cisco | Small Business Srp520-U Series Firmware | 1.1.0 |
| Cisco | Small Business Srp521W-U | All versions |
| Cisco | Small Business Srp526W-U | All versions |
| Cisco | Small Business Srp527W-U | All versions |
| Cisco | Small Business Srp540 Series Firmware | <= 1.02.01 |
| Cisco | Small Business Srp541W | All versions |
| Cisco | Small Business Srp546W | All versions |
| Cisco | Small Business Srp547W | All versions |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securitytracker.com/id?1026736
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securitytracker.com/id?1026736
FAQ
What is CVE-2012-0365?
CVE-2012-0365 is a vulnerability with a CVSS score of 9.0 (HIGH). Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4...
How severe is CVE-2012-0365?
CVE-2012-0365 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0365?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Small Business Srp520 Series Firmware, Cisco Small Business Srp521W, Cisco Small Business Srp526W, Cisco Small Business Srp527W, Cisco Small Business Srp520-U Series Firmware.