First published: Sun Dec 13 2015(Updated: )
Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Emergency Responder | =10.5\(1.10000.5\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6406 has been classified with a medium severity level due to its potential impact on system integrity.
To fix CVE-2015-6406, update your Cisco Emergency Responder to a version that contains the patch for this vulnerability.
CVE-2015-6406 can be exploited through crafted filenames that allow remote authenticated users to write to arbitrary files.
CVE-2015-6406 affects users of Cisco Emergency Responder version 10.5(1.10000.5).
While CVE-2015-6406 allows arbitrary file writing, its potential for complete system compromise depends on the file operations performed by the attacker.