Cisco Unified Communications Manager CVE-2013-3402 Command Injection Vulnerability
BID:61293
Info
Cisco Unified Communications Manager CVE-2013-3402 Command Injection Vulnerability
| Bugtraq ID: | 61293 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3402 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2013 12:00AM |
| Updated: | Jul 17 2013 12:00AM |
| Credit: | Lexfo |
| Vulnerable: |
Cisco Unified Communications Manager 8.6.3 Cisco Unified Communications Manager 8.6 Cisco Unified Communications Manager 8.0(1) Cisco Unified Communications Manager 7.1(5b)su5 Cisco Unified Communications Manager 7.1(5b)SU4 Cisco Unified Communications Manager 7.1(5b)su3 Cisco Unified Communications Manager 7.1(5b)SU2 Cisco Unified Communications Manager 7.1(5B) Cisco Unified Communications Manager 7.1(5A) Cisco Unified Communications Manager 7.1(5)Su1a Cisco Unified Communications Manager 7.1(5)Su1 Cisco Unified Communications Manager 7.1(5) Cisco Unified Communications Manager 7.1(3b)su2 Cisco Unified Communications Manager 7.1(3b)su1 Cisco Unified Communications Manager 7.1(3B) Cisco Unified Communications Manager 7.1(3A)Su1a Cisco Unified Communications Manager 7.1(3a)su1 Cisco Unified Communications Manager 7.1(3A) Cisco Unified Communications Manager 7.1(3) Cisco Unified Communications Manager 7.1(2B)Su1 Cisco Unified Communications Manager 7.1(2B) Cisco Unified Communications Manager 7.1(2a)su1 Cisco Unified Communications Manager 7.1(2A) Cisco Unified Communications Manager 7.1(2) Cisco Unified Communications Manager 7.1 |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager CVE-2013-3402 Command Injection Vulnerability
Cisco Unified Communications Manager is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands with the privileges of the database user in context of the affected application.
This issue is being tracked by Cisco bug ID CSCuh73440.
Versions prior to Unified Communications Manager 9.1(2) are affected.
Cisco Unified Communications Manager is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands with the privileges of the database user in context of the affected application.
This issue is being tracked by Cisco bug ID CSCuh73440.
Versions prior to Unified Communications Manager 9.1(2) are affected.
Exploit / POC
Cisco Unified Communications Manager CVE-2013-3402 Command Injection Vulnerability
The researchers who discovered this issue has developed an exploit code to demonstrate this issue. Please see the references for more information.
The researchers who discovered this issue has developed an exploit code to demonstrate this issue. Please see the references for more information.
Solution / Fix
Cisco Unified Communications Manager CVE-2013-3402 Command Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified Communications Manager CVE-2013-3402 Command Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco )