CVE Database
/

CVE-2017-6629

Back to search

CVE-2017-6629

Published: May 3, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device. The issue is due to improper sanitization of user-supplied input in HTTP POST parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. Cisco Bug IDs: CSCvd90118.

VendorProductVersions

n/a

Cisco Unity Connection

affected
Cisco Unity Connection

Weaknesses (CWE)

References

1038400
vdb-entry
x_refsource_SECTRACK
98286
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now