First published: Mon Jul 14 2014(Updated: )
Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =10.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3317 is considered a high severity vulnerability due to the potential for remote authenticated users to delete arbitrary files.
To fix CVE-2014-3317, it is recommended to upgrade to a version of Cisco Unified Communications Manager that addresses this vulnerability.
CVE-2014-3317 affects users of Cisco Unified Communications Manager version 10.0(1).
CVE-2014-3317 is a directory traversal vulnerability that allows deletion of files through crafted URLs.
The vulnerability in CVE-2014-3317 is caused by inadequate input validation in the Multiple Analyzer of the Dialed Number Analyzer component.