CVE-2013-6688 - CVE House
Back to Database
Status published Medium CVE-2013-6688

Directory traversal vulnerability in the license-upload interface in the Enterprise...

Vulnerability Description

Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka Bug ID CSCui58222.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-6688

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

unified communications manager
Vulnerable Versions:
0, 3.3\(5\), 3.3\(5\)sr1, 3.3\(5\)sr2a, 4.1\(3\), 4.1\(3\)sr1, 4.1\(3\)sr2, 4.1\(3\)sr3, 4.1\(3\)sr4, 4.2, 4.2.1, 4.2.2, 4.2.3, 4.2.3sr1, 4.2.3sr2, 4.2.3sr2b, 4.3, 4.3\(1\), 5.0, 5.1, 5.1\(1\), 5.1\(1b\), 5.1\(1c\), 5.1\(2\), 5.1\(2a\), 5.1\(2b\), 5.1\(3\), 5.1\(3a\), 5.1\(3c\), 5.1\(3d\), 5.1\(3e\), 5.1.2, 6.0, 6.0\(1\), 6.0\(1a\), 6.0\(1b\), 6.1\(1\), 6.1\(1a\), 6.1\(1b\), 6.1\(2\), 6.1\(2\)su1, 6.1\(2\)su1a, 6.1\(3\), 6.1\(3a\), 6.1\(3b\), 6.1\(3b\)su1, 6.1\(4\), 6.1\(4\)su1, 6.1\(4a\), 6.1\(4a\)su2, 6.1\(5\), 6.1\(5\)su1, 6.1\(5\)su2, 6.1\(5\)su3, 7.0\(1\)su1, 7.0\(1\)su1a, 7.0\(2\), 7.0\(2a\), 7.0\(2a\)su1, 7.0\(2a\)su2, 7.1\(2a\), 7.1\(2a\)su1, 7.1\(2b\), 7.1\(2b\)su1, 7.1\(3\), 7.1\(3a\), 7.1\(3a\)su1, 7.1\(3a\)su1a, 7.1\(3b\), 7.1\(3b\)su1, 7.1\(3b\)su2, 7.1\(5\), 7.1\(5\)su1, 7.1\(5\)su1a, 7.1\(5a\), 7.1\(5b\), 7.1\(5b\)su1, 7.1\(5b\)su1a, 7.1\(5b\)su2, 7.1\(5b\)su3, 7.1\(5b\)su4, 7.1\(5b\)su5, 7.1\(5b\)su6, 8.0, 8.0\(1\), 8.0\(2\), 8.0\(2a\), 8.0\(2b\), 8.0\(2c\), 8.0\(2c\)su1, 8.0\(3\), 8.0\(3a\), 8.0\(3a\)su1, 8.0\(3a\)su2, 8.0\(3a\)su3, 8.5, 8.5\(1\), 8.5\(1\)su1, 8.5\(1\)su2, 8.5\(1\)su3, 8.5\(1\)su4, 8.5\(1\)su5, 8.6, 8.6\(1\), 8.6\(1a\), 8.6\(2\), 8.6\(2a\), 8.6\(2a\)su1, 8.6\(2a\)su2, 8.6\(2a\)su3, 8.6\(3\), 8.6\(4\), 9.0\(1\)

Timeline

Official Publish: November 16th, 2013
Last Modified: September 17th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.