First published: Sun Dec 13 2015(Updated: )
Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Emergency Responder | =10.5\(3.10000.9\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6407 is classified as a high severity vulnerability due to its ability to allow remote file uploads to arbitrary locations.
To mitigate CVE-2015-6407, upgrade Cisco Emergency Responder to version 10.5(3.10000.10) or later.
CVE-2015-6407 affects users of Cisco Emergency Responder version 10.5(3.10000.9).
CVE-2015-6407 is a remote code execution vulnerability that allows file upload without proper authorization.
Yes, CVE-2015-6407 can be exploited by remote attackers who leverage crafted parameters to upload files.