Cisco Bug: CSCup76297 - CUCM DNA Multiple Analyzer allows upload of arbitrary file and extension
Aug 06, 2018
- Cisco Unified Communications Manager (CallManager)
Known Affected Releases
Symptom: A vulnerability in the Multiple Analyzer of the Dial Number Analyzer within the Cisco Unified Communications Manager could allow an authenticated, remote attacker to upload arbitrary files to a restricted location on the filesystem. The vulnerability is due to insufficient parameter validation. An attacker could exploit this vulnerability by submitting crafted data to the web server. Conditions: x An affected device with default configuration.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases