CVE-2009-0632
Summary
| CVE | CVE-2009-0632 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-03-12 15:20:49 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Unified Communications Manager | 4.1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.2 | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.2\(3\)sr1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.2\(3\)sr2b | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.2\(3\)sr3 | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.2\(3\)sr4 | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.3 | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.3\(1\)sr.1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.3\(2\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 4.3\(2\)sr1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.0 | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.1\(1\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.1\(2a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.1\(2b\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.1\(2\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.1\(3a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.1\(3c\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.1\(3d\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 5.1\(3\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.0 | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.0\(1a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.0\(1\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(1a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(1\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(2\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(2\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(3\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.0 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.0\(1\) | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Sends Passwords in Clear Text - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability [Products & Services] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Security Advisory: Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability [Products & Services] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| Cisco Unified Communications Manager IP Phone PAB Information Disclosure - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/52589 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Cisco Unified Communications Manager PAB Synchronizer Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.