// For flags

CVE-2009-0615

 

Severity Score

9.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to "invalid directory permissions."

Vulnerabilidad de salto de directorio en Cisco Application Networking Manager (ANM) anterior a v2.0 y Application Control Engine (ACE) Device Manager anterior a vA3(2.1) permite a usuarios atenticados remotamente leer o modificar ficheros de su elección a através de vectores sin especificar relacionados con "permisos de directorio inválido".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-02-18 CVE Reserved
  • 2009-02-25 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Application Control Engine Device Manager
Search vendor "Cisco" for product "Application Control Engine Device Manager"
<= 1.2
Search vendor "Cisco" for product "Application Control Engine Device Manager" and version " <= 1.2"
-
Affected
Cisco
Search vendor "Cisco"
Application Control Engine Device Manager
Search vendor "Cisco" for product "Application Control Engine Device Manager"
1.1
Search vendor "Cisco" for product "Application Control Engine Device Manager" and version "1.1"
-
Affected
Cisco
Search vendor "Cisco"
Application Networking Manager
Search vendor "Cisco" for product "Application Networking Manager"
<= 1.2
Search vendor "Cisco" for product "Application Networking Manager" and version " <= 1.2"
-
Affected
Cisco
Search vendor "Cisco"
Application Networking Manager
Search vendor "Cisco" for product "Application Networking Manager"
1.1
Search vendor "Cisco" for product "Application Networking Manager" and version "1.1"
-
Affected