CVE-2006-2166
Summary
| CVE | CVE-2006-2166 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-04 12:38:00 UTC |
| Updated | 2018-10-30 16:25:00 UTC |
| Description | Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any user with an expired password. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Unity Express | All | All | All | All |
| Hardware | Cisco | Unity Express | All | All | All | All |
| Application | Cisco | Unity Express Software | 1.1.1 | All | All | All |
| Application | Cisco | Unity Express Software | 2.1.1 | All | All | All |
| Application | Cisco | Unity Express Software | 2.2.2 | All | All | All |
| Application | Cisco | Unity Express Software | 1.1.1 | All | All | All |
| Application | Cisco | Unity Express Software | 2.1.1 | All | All | All |
| Application | Cisco | Unity Express Software | 2.2.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco - Networking, Cloud, and Cybersecurity Solutions | CISCO | www.cisco.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Cisco Unity Express Expired Password Privilege Escalation Vulnerability | BID | www.securityfocus.com | |
| 25165 | OSVDB | www.osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - Cisco Unity Express Lets Remote Authenticated Users Gain Administrative Privileges | SECTRACK | securitytracker.com | |
| Secunia - Advisories - Cisco Unity Express Expired Password Change Vulnerability | SECUNIA | secunia.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.