CVE-2013-6688: Cisco Unified Communications Manager
Medium severity, CVSS 6.3. EPSS: 2.1% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka Bug ID CSCui58222.
Affected products
- Cisco Unified Communications Manager: up to and including 9.1\(1\); version 3.3(5) only; version 3.3(5)sr1 only; version 3.3(5)sr2a only; version 4.1(3) only; version 4.1(3)sr1 only; …
Published 2013-11-18. Last modified 2026-06-17.