CVE-2008-3814
Summary
| CVE | CVE-2008-3814 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-08 22:00:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Unity | 4.0 | All | All | All |
| Application | Cisco | Unity | 4.0\(1\) | All | All | All |
| Application | Cisco | Unity | 4.0\(2\) | All | All | All |
| Application | Cisco | Unity | 4.0\(3\) | All | All | All |
| Application | Cisco | Unity | 4.0\(3\) | sr1 | All | All |
| Application | Cisco | Unity | 4.0\(4\) | All | All | All |
| Application | Cisco | Unity | 4.0\(4\) | sr1 | All | All |
| Application | Cisco | Unity | 4.0\(5\) | All | All | All |
| Application | Cisco | Unity | 4.1\(1\) | All | All | All |
| Application | Cisco | Unity | 4.2\(1\) | All | All | All |
| Application | Cisco | Unity | 5.0 | All | All | All |
| Application | Cisco | Unity | 5.0\(1\) | All | All | All |
| Application | Cisco | Unity | 7.0 | All | All | All |
| Application | Cisco | Unity | 7.0\(2\) | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Security Advisory: Authentication Bypass in Cisco Unity [Products & Services] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| Cisco Unity Remote Administration Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Security Response: VoIPshield Reported Vulnerabilities in Cisco Unity Server [Products & Services] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| Cisco Unity 7.0 Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco Unity Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Cisco Unity Authentication Bypass Bug Lets Remote Users View and Modify the Configuration - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Nothing found for Research Details Php?id=126 | af854a3a-2127-422b-91ae-364da2661108 | www.voipshield.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.