First published: Wed Dec 14 2016(Updated: )
A vulnerability in the Cisco Unified Reporting upload tool accessed via the Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to modify arbitrary files on the file system. More Information: CSCvb61698. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.168) 12.0(0.98000.178) 12.0(0.98000.399) 12.0(0.98000.510) 12.0(0.98000.536) 12.0(0.98500.7).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager Session Management Edition | =11.5\(1.11007.2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9210 is classified as a high-severity vulnerability due to the potential for unauthenticated remote file modification.
To fix CVE-2016-9210, update your Cisco Unified Communications Manager to a fixed release that addresses the vulnerability.
CVE-2016-9210 affects Cisco Unified Communications Manager version 11.5(1.11007.2).
Yes, CVE-2016-9210 can be exploited by an unauthenticated remote attacker.
The impact of CVE-2016-9210 allows attackers to modify arbitrary files on the system, potentially compromising integrity and availability.