CVE-2016-9208

MEDIUM

Cisco Emergency Responder <12.0.0 - Info Disclosure

Title source: llm

Description

A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected device. More Information: CSCva98951 CSCva98954 CSCvb57494. Known Affected Releases: 11.5(2.10000.5). Known Fixed Releases: 12.0(0.98000.14) 12.0(0.98000.16).

Scores

CVSS v3 6.5
EPSS 0.0101
EPSS Percentile 76.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-22
Status published

Affected Products (2)

cisco/emergency_responder
n/a/Cisco Emergency Responder < Cisco Emergency Responder

Timeline

Published Dec 14, 2016
Tracked Since Feb 18, 2026