CVE-2010-1571
Summary
| CVE | CVE-2010-1571 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-10 00:30:07 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Customer Response Solution | 5.0 | All | All | All |
| Application | Cisco | Customer Response Solution | 6.0 | All | All | All |
| Application | Cisco | Customer Response Solution | 7.0 | All | All | All |
| Application | Cisco | Unified Contact Center Express | 5.0 | All | All | All |
| Application | Cisco | Unified Contact Center Express | 6.0 | All | All | All |
| Application | Cisco | Unified Contact Center Express | 7.0 | All | All | All |
| Application | Cisco | Unified Ip Interactive Voice Response | 5.0 | All | All | All |
| Application | Cisco | Unified Ip Interactive Voice Response | 6.0 | All | All | All |
| Application | Cisco | Unified Ip Interactive Voice Response | 7.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Cisco Unified Contact Center Express Directory Traversal Flaw Lets Remote Users View Arbitrary Files on the Target System | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Unified Contact Center Express Bootstrap Service Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco Security Advisory: Vulnerabilities in Cisco Unified Contact Center Express - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.