Lucene search

K
cveMitreCVE-2008-4545
HistoryOct 13, 2008 - 8:00 p.m.

CVE-2008-4545

2008-10-1320:00:02
CWE-264
mitre
web.nvd.nist.gov
31
cisco
unity
directory
weak permissions
vulnerability
cve-2008-4545
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

5.8

Confidence

Low

EPSS

0.002

Percentile

57.5%

Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8 uses weak permissions for the D:\CommServer\Reports directory, which allows remote authenticated users to obtain sensitive information by reading files in this directory.

Affected configurations

Nvd
Node
ciscounityRangeโ‰ค4.2\(1\)
OR
ciscounityRangeโ‰ค5.0\(1\)
OR
ciscounityRangeโ‰ค7.0\(2\)
OR
ciscounityMatch4.0
OR
ciscounityMatch4.0\(1\)
OR
ciscounityMatch4.0\(2\)
OR
ciscounityMatch4.0\(3\)
OR
ciscounityMatch4.0\(3\)sr2
OR
ciscounityMatch4.0\(4\)
OR
ciscounityMatch4.0\(4\)sr1
OR
ciscounityMatch4.0\(5\)
OR
ciscounityMatch4.1\(1\)
OR
ciscounityMatch5.0
OR
ciscounityMatch7.0
VendorProductVersionCPE
ciscounity*cpe:2.3:a:cisco:unity:*:*:*:*:*:*:*:*
ciscounity4.0cpe:2.3:a:cisco:unity:4.0:*:*:*:*:*:*:*
ciscounity4.0(1)cpe:2.3:a:cisco:unity:4.0\(1\):*:*:*:*:*:*:*
ciscounity4.0(2)cpe:2.3:a:cisco:unity:4.0\(2\):*:*:*:*:*:*:*
ciscounity4.0(3)cpe:2.3:a:cisco:unity:4.0\(3\):*:*:*:*:*:*:*
ciscounity4.0(3)cpe:2.3:a:cisco:unity:4.0\(3\):sr2:*:*:*:*:*:*
ciscounity4.0(4)cpe:2.3:a:cisco:unity:4.0\(4\):*:*:*:*:*:*:*
ciscounity4.0(4)cpe:2.3:a:cisco:unity:4.0\(4\):sr1:*:*:*:*:*:*
ciscounity4.0(5)cpe:2.3:a:cisco:unity:4.0\(5\):*:*:*:*:*:*:*
ciscounity4.1(1)cpe:2.3:a:cisco:unity:4.1\(1\):*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

5.8

Confidence

Low

EPSS

0.002

Percentile

57.5%

Related for CVE-2008-4545