CVE-2011-3315 EXPLOIT
7.8
HIGH · CVSS 2.0 · EPSS 25.7% (pctl 98)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
Scoring
| CVSS | 7.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
| EPSS | 25.75% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-10-27 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| cisco | unified ccx |
| cisco | unified communications manager |
| cisco | unified ip interactive voice response |
| cisco | unified ip ivr |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco - 'file' Directory Traversal | 2011-10-26 |
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucm
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucm
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx
→ the Explorer · watch your stack · NVD