Cisco Unity With Exchange Default User Accounts and Passwords Vulnerability
BID:11954
Info
Cisco Unity With Exchange Default User Accounts and Passwords Vulnerability
| Bugtraq ID: | 11954 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | This issue was disclosed by Cisco. |
| Vulnerable: |
Cisco Unity Server 4.0 Cisco Unity Server 3.3 Cisco Unity Server 3.2 Cisco Unity Server 3.1 Cisco Unity Server 3.0 Cisco Unity Server 2.46 Cisco Unity Server 2.4 Cisco Unity Server 2.3 Cisco Unity Server 2.2 Cisco Unity Server 2.1 Cisco Unity Server 2.0 |
| Not Vulnerable: | |
Discussion
Cisco Unity With Exchange Default User Accounts and Passwords Vulnerability
It is reported that vulnerable Unity systems contain default user accounts and passwords that can be used by an attacker to gain unauthorized access. This issue only arises when Unity is integrated with Microsoft Exchange.
Unauthorized attakers may use these accounts to gain administrative access to vulnerable systems. Some accounts can allow attackers to disclose messages going to and from external voicemail systems.
It is reported that vulnerable Unity systems contain default user accounts and passwords that can be used by an attacker to gain unauthorized access. This issue only arises when Unity is integrated with Microsoft Exchange.
Unauthorized attakers may use these accounts to gain administrative access to vulnerable systems. Some accounts can allow attackers to disclose messages going to and from external voicemail systems.
Exploit / POC
Cisco Unity With Exchange Default User Accounts and Passwords Vulnerability
An exploit is not required to carry out this attack.
An exploit is not required to carry out this attack.
Solution / Fix
Cisco Unity With Exchange Default User Accounts and Passwords Vulnerability
Solution:
Cisco has released an advisory (63568) that includes a workaround to address this issue. Cisco plans to release Unity 4.0(5) in the near future. This version will include a fix for this issue, however, it is reported that the fix will only apply to new installs. Users upgrading to Unity 4.0(5) must apply the workaround provided by the vendor.
Solution:
Cisco has released an advisory (63568) that includes a workaround to address this issue. Cisco plans to release Unity 4.0(5) in the near future. This version will include a fix for this issue, however, it is reported that the fix will only apply to new installs. Users upgrading to Unity 4.0(5) must apply the workaround provided by the vendor.
References
Cisco Unity With Exchange Default User Accounts and Passwords Vulnerability
References:
References:
- Cisco Security Advisory: Cisco Unity with Exchange Has Default Passwords (Cisco)
- Cisco Unity Integrated with Exchange Has Default Password (Cisco Systems Product Security Incident Response Team
)