5
CVSSv2

CVE-2015-0745

Published: 30/05/2015 Updated: 04/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco Headend System Release allows remote malicious users to read temporary script files or archive files, and consequently obtain sensitive information, via a crafted header in an HTTP request, aka Bug ID CSCus44909.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco headend digital broadband delivery system -

cisco headend system release 3.7

cisco headend system release 2.5

cisco headend system release 2.7

cisco headend system release 3.2

cisco headend system release 3.5

cisco headend system release i4.3

Vendor Advisories

A vulnerability in Cisco Headend System Release could allow an unauthenticated, remote attacker to download temporary script files The vulnerability is due to improper input validation of the HTTP request header An attacker could exploit this vulnerability by manipulating the URL of an HTTP request An exploit could allow the attacker to expose ...