MEDIUM · 5.0

CVE-2013-3426

The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh5...

Vulnerability Description

The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoUnified Ip Phones 9900 Series Firmware-
CiscoUnified Ip Phone 9951All versions
CiscoUnified Ip Phone 9971All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3426?

CVE-2013-3426 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh5...

How severe is CVE-2013-3426?

CVE-2013-3426 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3426?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Ip Phones 9900 Series Firmware, Cisco Unified Ip Phone 9951, Cisco Unified Ip Phone 9971.