Vulnerability CVE-2013-7030


Published: 2013-12-12

Description:
** DISPUTED ** The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue.

See advisories in our WLB2 database:
Topic
Author
Date
High
Cisco Unified Communications Manager - TFTP Service
Daniel Svartman
12.12.2013

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Cisco -> Unified communications manager 

 References:
http://www.exploit-db.com/exploits/30237/
http://xforce.iss.net/xforce/xfdb/89649

Copyright 2024, cxsecurity.com

 

Back to Top