← Back

CVE-2020-3130

nvd nist
Published: Sep 23, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web management interface. A successful exploit could allow the attacker to overwrite files on the underlying filesystem of an affected system. Valid administrator credentials are required to access the system.

Affected (2)

1 product
Unity Connection
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
From 11.0 to 11.5su7
From 12.0 to 12.5su2

Timeline

No history available yet.