MEDIUM · 4.0

CVE-2015-6407

Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

Vulnerability Description

Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CiscoEmergency Responder10.5\(3.10000.9\)

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-6407?

CVE-2015-6407 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

How severe is CVE-2015-6407?

CVE-2015-6407 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-6407?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Emergency Responder.