peter bassill · operator
$ cve CVE-2011-3315 JSON

CVE-2011-3315 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 25.7% (pctl 98)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS25.75% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2011-10-27
Last modified2026-06-16

Affected (4)

VendorProduct
ciscounified ccx
ciscounified communications manager
ciscounified ip interactive voice response
ciscounified ip ivr

Public exploits

SourceTitleDate
exploit-dbCisco - 'file' Directory Traversal2011-10-26

References

→ the Explorer  ·  watch your stack  ·  NVD