CVE-2013-1240
UnknownEPSS 0.30%
Last modified
CVE-2013-1240 is a vulnerability of currently unknown severity. The command-line interface in Cisco Unified Communications Manager (CUCM) does not properly validate input, which allows local users to read arbitrary files via unspecified vectors, aka Bug ID CSCue25770.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
The command-line interface in Cisco Unified Communications Manager (CUCM) does not properly validate input, which allows local users to read arbitrary files via unspecified vectors, aka Bug ID CSCue25770.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Communications Manager | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1240?
The command-line interface in Cisco Unified Communications Manager (CUCM) does not properly validate input, which allows local users to read arbitrary files via unspecified vectors, aka Bug ID CSCue25770.
How severe is CVE-2013-1240?
Severity scoring for CVE-2013-1240 is pending analysis. The EPSS model estimates a 0.30% probability of exploitation in the next 30 days.
How do I fix CVE-2013-1240?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1231The HTTP implementation in Cisco WebEx Node for MCS and WebE…
- CVE-2013-1232The HTTP implementation in Cisco WebEx Node for MCS, WebEx M…
- CVE-2013-1233Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-1234The SNMP module in Cisco IOS XR allows remote authenticated …
- CVE-2013-1235Cisco Wireless LAN Controller (WLC) devices do not properly …
- CVE-2013-1236Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allo…
- CVE-2013-1241The ISM module in Cisco IOS on ISR G2 routers does not prope…
- CVE-2013-1242Memory leak in the web framework in the server in Cisco Unif…
- CVE-2013-1243The IP stack in Cisco Intrusion Prevention System (IPS) Soft…
- CVE-2013-1244Cross-site scripting (XSS) vulnerability in the portal modul…
- CVE-2013-1245The user-management page in Cisco WebEx Social relies on cli…
- CVE-2013-1246Cisco TelePresence System Software does not properly handle …
Are you affected by CVE-2013-1240?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
