CVE-2016-9208
MEDIUMCisco Emergency Responder <12.0.0 - Info Disclosure
Title source: llmDescription
A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected device. More Information: CSCva98951 CSCva98954 CSCvb57494. Known Affected Releases: 11.5(2.10000.5). Known Fixed Releases: 12.0(0.98000.14) 12.0(0.98000.16).
Scores
CVSS v3
6.5
EPSS
0.0101
EPSS Percentile
76.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-22
Status
published
Affected Products (2)
cisco/emergency_responder
n/a/Cisco Emergency Responder
< Cisco Emergency Responder
Timeline
Published
Dec 14, 2016
Tracked Since
Feb 18, 2026