Cisco Unity Remote Administration Authentication Bypass Vulnerability
BID:31638
Info
Cisco Unity Remote Administration Authentication Bypass Vulnerability
| Bugtraq ID: | 31638 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-3814 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2008 12:00AM |
| Updated: | Oct 09 2008 04:18PM |
| Credit: | VoIPshield Systems |
| Vulnerable: |
Cisco Unity 7.0 Cisco Unity 5.0 Cisco Unity 4.0 |
| Not Vulnerable: |
Cisco Unity 7.0 ES8 Cisco Unity 5.0 ES53 Cisco Unity 4.0 ES161 |
Discussion
Cisco Unity Remote Administration Authentication Bypass Vulnerability
Cisco Unity is prone to an authentication-bypass vulnerability.
Exploiting this issue can allow remote attackers to gain unauthorized administrative privileges. This issue is being tracked by Cisco Bug ID CSCsr86943.
Versions prior to the following are vulnerable:
Cisco Unity 4.0 ES161 for the 4.x release
Cisco Unity 5.0 ES53 for the 5.x release
Cisco Unity 7.0 ES8 for the 7.x release
Cisco Unity is prone to an authentication-bypass vulnerability.
Exploiting this issue can allow remote attackers to gain unauthorized administrative privileges. This issue is being tracked by Cisco Bug ID CSCsr86943.
Versions prior to the following are vulnerable:
Cisco Unity 4.0 ES161 for the 4.x release
Cisco Unity 5.0 ES53 for the 5.x release
Cisco Unity 7.0 ES8 for the 7.x release
Exploit / POC
Cisco Unity Remote Administration Authentication Bypass Vulnerability
Attackers may exploit this issue via a web browser.
Attackers may exploit this issue via a web browser.
Solution / Fix
Cisco Unity Remote Administration Authentication Bypass Vulnerability
Solution:
Vendor fixes are available. Please see the references for details.
Solution:
Vendor fixes are available. Please see the references for details.
References
Cisco Unity Remote Administration Authentication Bypass Vulnerability
References:
References: