CVE-2012-6609: Path Traversal
Directory traversal vulnerability in agetlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6609?
CVE-2012-6609 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2012-6609?
To fix CVE-2012-6609, upgrade the Polycom HDX Video End Points to version 3.0.4 or later and UC APL to version 2.7.1.J or later.
What types of attacks can exploit CVE-2012-6609?
CVE-2012-6609 can be exploited through directory traversal attacks that allow remote attackers to read arbitrary files.
Which Polycom products are affected by CVE-2012-6609?
CVE-2012-6609 affects Polycom HDX Video End Points before version 3.0.4 and UC APL before version 2.7.1.J.
Can CVE-2012-6609 lead to other vulnerabilities?
Yes, exploiting CVE-2012-6609 can potentially lead to further attacks if sensitive files such as credentials are accessed.