CVE-2016-9208

MEDIUM

Cisco Emergency Responder <12.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected device. More Information: CSCva98951 CSCva98954 CSCvb57494. Known Affected Releases: 11.5(2.10000.5). Known Fixed Releases: 12.0(0.98000.14) 12.0(0.98000.16).

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94800
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037426

Scores

CVSS v3 6.5
EPSS 0.0269
EPSS Percentile 84.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
cisco/emergency_responder 11.5\(2.10000.5\)
n/a/Cisco Emergency Responder Cisco Emergency Responder
Published Dec 14, 2016
Tracked Since Feb 18, 2026