Cisco Unified MeetingPlace Arbitrary File Download Vulnerability

Related Vulnerabilities: CVE-2015-0764  

A vulnerability in the Cisco Unified MeetingPlace application could allow an unauthenticated, remote attacker to retrieve arbitrary files. The vulnerability is due to improper handling of requests for resources by an affected device. An unauthenticated, remote attacker could exploit this vulnerability to download arbitrary files from a targeted device. A successful exploit could be used to conduct further attacks. Cisco has confirmed the vulnerability and released software updates. Attackers must send requests to vulnerable systems, possibly limiting the potential for exploitation in environments that restrict network access from untrusted networks.