CVE-2009-0615

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
26/02/2009
Last modified:
09/04/2025

Description

Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to "invalid directory permissions."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:application_control_engine_device_manager:*:*:*:*:*:*:*:* 1.2 (including)
cpe:2.3:a:cisco:application_control_engine_device_manager:1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_networking_manager:*:*:*:*:*:*:*:* 1.2 (including)
cpe:2.3:a:cisco:application_networking_manager:1.1:*:*:*:*:*:*:*