CVE-2017-6629
MEDIUMCisco Unity Connection - Path Traversal
Title source: ruleDescription
A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device. The issue is due to improper sanitization of user-supplied input in HTTP POST parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. Cisco Bug IDs: CSCvd90118.
Scores
CVSS v3
5.3
EPSS
0.0114
EPSS Percentile
78.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-22
Status
published
Affected Products (2)
cisco/unity_connection
n/a/Cisco Unity Connection
< Cisco Unity Connection
Timeline
Published
May 03, 2017
Tracked Since
Feb 18, 2026