CVE-2009-0615
 
Severity Score
9.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to "invalid directory permissions."
Vulnerabilidad de salto de directorio en Cisco Application Networking Manager (ANM) anterior a v2.0 y Application Control Engine (ACE) Device Manager anterior a vA3(2.1) permite a usuarios atenticados remotamente leer o modificar ficheros de su elección a através de vectores sin especificar relacionados con "permisos de directorio inválido".
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-02-18 CVE Reserved
- 2009-02-25 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/33903 | Vdb Entry | |
http://www.securitytracker.com/id?1021770 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc84.shtml | 2009-03-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Application Control Engine Device Manager Search vendor "Cisco" for product "Application Control Engine Device Manager" | <= 1.2 Search vendor "Cisco" for product "Application Control Engine Device Manager" and version " <= 1.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Application Control Engine Device Manager Search vendor "Cisco" for product "Application Control Engine Device Manager" | 1.1 Search vendor "Cisco" for product "Application Control Engine Device Manager" and version "1.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Application Networking Manager Search vendor "Cisco" for product "Application Networking Manager" | <= 1.2 Search vendor "Cisco" for product "Application Networking Manager" and version " <= 1.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Application Networking Manager Search vendor "Cisco" for product "Application Networking Manager" | 1.1 Search vendor "Cisco" for product "Application Networking Manager" and version "1.1" | - |
Affected
|