Lucene search

K
ciscoCiscoCISCO-SA-CUCM-INF-DISC-WCXZNJL2
HistoryApr 07, 2021 - 4:00 p.m.

Cisco Unified Communications Manager Information Disclosure Vulnerability

2021-04-0716:00:00
tools.cisco.com
47
cisco unified communications manager
information disclosure
vulnerability
unauthorized access
sensitive information
affected devices
cisco security advisory
software

EPSS

0.002

Percentile

51.5%

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an affected device.

The vulnerability is due to improper inclusion of sensitive information in downloadable files. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to obtain hashed credentials of system users. To exploit this vulnerability an attacker would need to have valid user credentials with elevated privileges.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-inf-disc-wCxZNjL2 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-inf-disc-wCxZNjL2”]

Affected configurations

Vulners
Node
ciscounified_communications_managerMatchany
OR
ciscounity_connectionMatchany
OR
ciscounified_communications_managerMatchany
OR
ciscounity_connectionMatchany
VendorProductVersionCPE
ciscounified_communications_manageranycpe:2.3:a:cisco:unified_communications_manager:any:*:*:*:*:*:*:*
ciscounity_connectionanycpe:2.3:a:cisco:unity_connection:any:*:*:*:*:*:*:*

EPSS

0.002

Percentile

51.5%

Related for CISCO-SA-CUCM-INF-DISC-WCXZNJL2