Cisco CallManager Express SIP User Directory Information Disclosure Vulnerability
BID:19309
CVE-2006-4032 |Info
Cisco CallManager Express SIP User Directory Information Disclosure Vulnerability
| Bugtraq ID: | 19309 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2006 12:00AM |
| Updated: | Aug 03 2006 05:46PM |
| Credit: | The vendor credits Dave Endler with discovery of this vulnerability. |
| Vulnerable: |
Cisco CallManager Express 3.0 |
| Not Vulnerable: | |
Discussion
Cisco CallManager Express SIP User Directory Information Disclosure Vulnerability
Cisco CallManager Express is prone to an information-disclosure vulnerability because the application fails to protect sensitive data from an attacker.
An attacker could exploit this issue to retrieve potentially sensitive information that may aid in further attacks.
Cisco CallManager Express is prone to an information-disclosure vulnerability because the application fails to protect sensitive data from an attacker.
An attacker could exploit this issue to retrieve potentially sensitive information that may aid in further attacks.
Exploit / POC
Cisco CallManager Express SIP User Directory Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco CallManager Express SIP User Directory Information Disclosure Vulnerability
Solution:
Fixes are available. Please see the referenced Cisco advisory for details.
Solution:
Fixes are available. Please see the referenced Cisco advisory for details.
References
Cisco CallManager Express SIP User Directory Information Disclosure Vulnerability
References:
References: