CVE-2009-1161
Summary
| CVE | CVE-2009-1161 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-21 14:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Ciscoworks Common Services | 3.0.3 | All | windows | All |
| Application | Cisco | Ciscoworks Common Services | 3.0.4 | All | windows | All |
| Application | Cisco | Ciscoworks Common Services | 3.0.5 | All | windows | All |
| Application | Cisco | Ciscoworks Common Services | 3.0.6 | All | windows | All |
| Application | Cisco | Ciscoworks Common Services | 3.1 | All | windows | All |
| Application | Cisco | Ciscoworks Common Services | 3.1.1 | All | windows | All |
| Application | Cisco | Ciscoworks Common Services | 3.2 | All | windows | All |
| Application | Cisco | Ciscoworks Health And Utilization Monitor | 1.0 | All | All | All |
| Application | Cisco | Ciscoworks Health And Utilization Monitor | 1.1 | All | All | All |
| Application | Cisco | Ciscoworks Lan Management Solution | 2.5 | All | All | All |
| Application | Cisco | Ciscoworks Lan Management Solution | 2.6 | All | All | All |
| Application | Cisco | Ciscoworks Lan Management Solution | 3.0 | All | All | All |
| Application | Cisco | Ciscoworks Lan Management Solution | 3.1 | All | All | All |
| Application | Cisco | Ciscoworks Qos Policy Manager | 4.0 | All | All | All |
| Application | Cisco | Ciscoworks Qos Policy Manager | 4.1 | All | All | All |
| Application | Cisco | Ciscoworks Voice Manager | 3.0 | All | All | All |
| Application | Cisco | Ciscoworks Voice Manager | 3.1 | All | All | All |
| Application | Cisco | Security Manager | 3.0 | All | All | All |
| Application | Cisco | Security Manager | 3.1 | All | All | All |
| Application | Cisco | Security Manager | 3.2 | All | All | All |
| Application | Cisco | Telepresence Readiness Assessment Manager | 1.0 | All | All | All |
| Application | Cisco | Unified Operations Manager | 1.0 | All | All | All |
| Application | Cisco | Unified Operations Manager | 1.1 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.0 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.1 | All | All | All |
| Application | Cisco | Unified Provisioning Manager | 1.0 | All | All | All |
| Application | Cisco | Unified Provisioning Manager | 1.1 | All | All | All |
| Application | Cisco | Unified Provisioning Manager | 1.2 | All | All | All |
| Application | Cisco | Unified Provisioning Manager | 1.3 | All | All | All |
| Application | Cisco | Unified Service Monitor | 1.0 | All | All | All |
| Application | Cisco | Unified Service Monitor | 1.1 | All | All | All |
| Application | Cisco | Unified Service Monitor | 2.0 | All | All | All |
| Application | Cisco | Unified Service Monitor | 2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CiscoWorks TFTP Directory Traversal Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000032.html | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| Cisco Security Advisory: CiscoWorks TFTP Directory Traversal Vulnerability - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - CiscoWorks Bug in TFTP Service Lets Remote Users Traverse the Directory | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| osvdb.org/54616 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| JVN#62527913 Directory traversal vulnerability in multiple Cisco Systems products | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CiscoWorks Common Services TFTP Server Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.