First published: Sat Mar 28 2015(Updated: )
Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CallManager Express | =9.1\(2.1000.28\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0680 has a Medium severity rating due to its potential to allow remote authenticated users to access arbitrary files.
To fix CVE-2015-0680, users should upgrade to a fixed version of Cisco Unified Call Manager that addresses the vulnerability.
CVE-2015-0680 affects users of Cisco Unified Call Manager version 9.1(2.1000.28) specifically.
CVE-2015-0680 allows remote authenticated users to read arbitrary files, which may lead to information disclosure.
CVE-2015-0680 is specific to version 9.1(2.1000.28) and may not be present or impactful in later versions.