Path traversal in Unified Communications Manager (CallManager) and Cisco Unified Communications Manager Session Management Edition - CVE-2020-3177
Published: April 16, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Tool for Auto-Registered Phones Support (TAPS). A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Cisco Unified Communications Manager Session Management Edition
How to mitigate CVE-2020-3177
Cisco Unified Communications Manager Session Management Edition - addressed in versions 10.5.2 SU9, 11.5.1 SU7, 12.5.1 SU2