CVE-2020-3130

MEDIUM

Cisco Unity Connection - File Overwrite

Title source: llm
STIX 2.1

Description

A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web management interface. A successful exploit could allow the attacker to overwrite files on the underlying filesystem of an affected system. Valid administrator credentials are required to access the system.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 27.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-20
Status published
Products (1)
cisco/unity_connection 11.0 - 11.5su7
Published Sep 23, 2020
Tracked Since Feb 18, 2026