Cisco CallManager CCMAdmin Remote Privilege Escalation Vulnerability
BID:16293
Info
Cisco CallManager CCMAdmin Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 16293 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2006 12:00AM |
| Updated: | Feb 07 2006 08:55PM |
| Credit: | CNLabs of Switzerland reported this issue to the vendor. |
| Vulnerable: |
Cisco Call Manager 4.1 (3)SR1 Cisco Call Manager 4.1 (3)ES07 Cisco Call Manager 4.1 (2)ES33 Cisco Call Manager 4.0 (2a)SR2b Cisco Call Manager 4.0 (2a)ES40 Cisco Call Manager 4.0 Cisco Call Manager 3.3 (5) Cisco Call Manager 3.3 (4)ES25 Cisco Call Manager 3.3 (3)ES61 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 |
| Not Vulnerable: |
Cisco Call Manager 4.1 (3)SR2 Cisco Call Manager 4.1 (3)ES32 Cisco Call Manager 4.1 (2)ES55 Cisco Call Manager 4.0 (2a)SR2c Cisco Call Manager 4.0 (2a)ES62 Cisco Call Manager 3.3 (5)SR1a Cisco Call Manager 3.3 (5)ES30 |
Discussion
Cisco CallManager CCMAdmin Remote Privilege Escalation Vulnerability
Cisco CallManager is susceptible to a remote privilege escalation vulnerability. This issue is due to a failure of the application to properly enforce access controls. This issue is only exploitable when Multi Level Administration is enabled, and users are granted read-only administrative access via the CCMAdmin Web interface.
This issue allows remote attackers to gain full read-write administrative access to the Web interface of Cisco CallManager.
Cisco CallManager is susceptible to a remote privilege escalation vulnerability. This issue is due to a failure of the application to properly enforce access controls. This issue is only exploitable when Multi Level Administration is enabled, and users are granted read-only administrative access via the CCMAdmin Web interface.
This issue allows remote attackers to gain full read-write administrative access to the Web interface of Cisco CallManager.
Exploit / POC
Cisco CallManager CCMAdmin Remote Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Cisco CallManager CCMAdmin Remote Privilege Escalation Vulnerability
Solution:
The vendor has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further information on obtaining fixes.
Solution:
The vendor has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further information on obtaining fixes.
References
Cisco CallManager CCMAdmin Remote Privilege Escalation Vulnerability
References:
References:
- CallManager Product Page (Cisco)
- Cisco Security Advisory: Cisco Call Manager Privilege Escalation (Cisco Systems Product Security Incident Response Team
)