CVE-2012-0365
Last modified
CVE-2012-0365 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arbitrary directories via unspecified vectors, aka Bug ID CSCtw56009.. EPSS estimates a 3.33% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arbitrary directories via unspecified vectors, aka Bug ID CSCtw56009.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Small Business Srp520 Series Firmware | <= 1.01.24 |
| Cisco | Small Business Srp520 Series Firmware | 1.01.01 |
| Cisco | Small Business Srp520 Series Firmware | 1.01.09 |
| Cisco | Small Business Srp520 Series Firmware | 1.01.11 |
| Cisco | Small Business Srp520 Series Firmware | 1.01.19 |
| Cisco | Small Business Srp520 Series Firmware | 1.01.23 |
| Cisco | Small Business Srp521w | All versions |
| Cisco | Small Business Srp526w | All versions |
| Cisco | Small Business Srp527w | All versions |
| Cisco | Small Business Srp520-U Series Firmware | 1.1.0 |
| Cisco | Small Business Srp521w-U | All versions |
| Cisco | Small Business Srp526w-U | All versions |
| Cisco | Small Business Srp527w-U | All versions |
| Cisco | Small Business Srp540 Series Firmware | <= 1.02.01 |
| Cisco | Small Business Srp540 Series Firmware | 1.02.00.023 |
| Cisco | Small Business Srp541w | All versions |
| Cisco | Small Business Srp546w | All versions |
| Cisco | Small Business Srp547w | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0365?
How severe is CVE-2012-0365?
How do I fix CVE-2012-0365?
Are you affected by CVE-2012-0365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
