漏洞描述 Cisco Emergency Responder(ER)是美国思科(Cisco)公司的一套IP通信系统中的应急呼叫软件。该软件提供实时定位跟踪数据库和呼叫者的位置等功能。 Cisco ER 10.5(3.10000.9)版本中存在安全漏洞。远程攻击者可借助特制的参数利用该漏洞向任意位置上传文件。
相关漏洞推荐 Cisco Secure Firewall Management Center和Cisco Secure Firewall Threat Defense 操作系统命令注入漏洞 POC CVE-2001-0537: Cisco IOS HTTP Configuration - Authentication Bypass POC CVE-2009-1558: Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion POC CVE-2011-3315: Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal POC CVE-2013-5528: Cisco Unified Communications Manager 7/8/9 - Directory Traversal POC CVE-2018-0127: Cisco RV132W/RV134W Router - Information Disclosure POC CVE-2018-0296: Cisco ASA - Local File Inclusion POC CVE-2019-1653: Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure POC CVE-2019-1821: Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution POC CVE-2019-1898: Cisco RV110W RV130W RV215W Router - Information leakage POC CVE-2019-1943: Cisco Small Business 200,300 and 500 Series Switches - Open Redirect POC CVE-2020-16139: Cisco Unified IP Conference Station 7937G - Denial-of-Service POC CVE-2020-26073: Cisco SD-WAN vManage Software - Local File Inclusion