CiscoWorks TFTP Directory Traversal Vulnerability
CiscoWorks Common Services contains a vulnerability that could allow an unauthenticated remote attacker to access application and host operating system files.
Cisco has released free software updates that address this vulnerability. A workaround that mitigates this vulnerability is available.
Vulnerable Products
Products that have TFTP services enabled and that run CiscoWorks Common Services versions 3.0.x, 3.1.x, and 3.2.x are vulnerable. Only CiscoWorks Common Services systems running on Microsoft Windows operating systems are affected.