[Japanese]
|
JVNDB-2009-000032
|
Directory traversal vulnerability in multiple Cisco Systems products
|
Multiple products provided by Cisco Systems contain a directory traversal vulnerablility.
Multiple Cisco Systems products are vulnerable to directory traversal due to an issue in CiscoWorks Common Services.
Jun Okada of NTT DATA SECURITY CORPORATION reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 10.0 (High) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Complete
- Integrity Impact: Complete
- Availability Impact: Complete
|
|
Cisco Systems, Inc.
- CiscoWorks Common Services (CWCS) 3.0.x
- CiscoWorks Common Services (CWCS) 3.1.x
- CiscoWorks Common Services (CWCS) 3.2.x
|
|
A remote attacker could view or alter files on the target server.
|
[Update the software]
Update to the latest version of CiscoWorks Common Services according the information provided by the vendor.
[Workarounds]
As a workaround to this vulnerability, disable the TFTP service until the software is updated.
|
Cisco Systems, Inc.
|
- Path Traversal(CWE-22) [IPA Evaluation]
|
- CVE-2009-1161
|
- JVN : JVN#62527913
- National Vulnerability Database (NVD) : CVE-2009-1161
- IPA SECURITY ALERTS : Security Alert for Vulnerability in Multiple Cisco Systems Products
- SecurityFocus : 35040
- SecurityTracker : 1022263
- JVN iPedia (Japanese) : JVNDB-2009-000032
|
- [2009/05/29]
Web page published
|