CVE-2013-6688: Cisco Unified Communications Manager

Medium severity, CVSS 6.3. EPSS: 2.1% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka Bug ID CSCui58222.

Affected products

  • Cisco Unified Communications Manager: up to and including 9.1\(1\); version 3.3(5) only; version 3.3(5)sr1 only; version 3.3(5)sr2a only; version 4.1(3) only; version 4.1(3)sr1 only; …

Published 2013-11-18. Last modified 2026-06-17.