#VU26981 Path traversal in Unified Communications Manager (CallManager) and Cisco Unified Communications Manager Session Management Edition - CVE-2020-3177
Published: April 16, 2020
Unified Communications Manager (CallManager)
Cisco Unified Communications Manager Session Management Edition
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Tool for Auto-Registered Phones Support (TAPS). A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.