CVE-2015-6406: Path Traversal
Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6406?
CVE-2015-6406 has been classified with a medium severity level due to its potential impact on system integrity.
How do I fix CVE-2015-6406?
To fix CVE-2015-6406, update your Cisco Emergency Responder to a version that contains the patch for this vulnerability.
What types of attacks can exploit CVE-2015-6406?
CVE-2015-6406 can be exploited through crafted filenames that allow remote authenticated users to write to arbitrary files.
Who is affected by CVE-2015-6406?
CVE-2015-6406 affects users of Cisco Emergency Responder version 10.5(1.10000.5).
Can CVE-2015-6406 lead to complete system compromise?
While CVE-2015-6406 allows arbitrary file writing, its potential for complete system compromise depends on the file operations performed by the attacker.