Cisco Unified Communications Manager CVE-2013-3434 Local Privilege Escalation Vulnerability
BID:61296
Info
Cisco Unified Communications Manager CVE-2013-3434 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 61296 |
| Class: | Design Error |
| CVE: |
CVE-2013-3434 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 17 2013 12:00AM |
| Updated: | Mar 19 2015 09:16AM |
| Credit: | This issue was disclosed by Lexfo security firm during the SSTIC 2013 IT security conference. |
| Vulnerable: |
Cisco Unified Communications Manager 8.6.3 Cisco Unified Communications Manager 8.6(2a)su1 Cisco Unified Communications Manager 8.6 Cisco Unified Communications Manager 8.5(1)SU2 Cisco Unified Communications Manager 8.5(1)SU1 Cisco Unified Communications Manager 8.5(1) Cisco Unified Communications Manager 8.5 Cisco Unified Communications Manager 8.0(3a)su3 Cisco Unified Communications Manager 8.0(3a)SU2 Cisco Unified Communications Manager 8.0(3a)su1 Cisco Unified Communications Manager 8.0(3a) Cisco Unified Communications Manager 8.0(3) Cisco Unified Communications Manager 8.0(2C)Su1 Cisco Unified Communications Manager 8.0(2C) Cisco Unified Communications Manager 8.0(1) Cisco Unified Communications Manager 8.0(0.98000.106) Cisco Unified Communications Manager 7.1(5b)su5 Cisco Unified Communications Manager 7.1(5b)SU4 Cisco Unified Communications Manager 7.1(5b)su3 Cisco Unified Communications Manager 7.1(5b)SU2 Cisco Unified Communications Manager 7.1(5B) Cisco Unified Communications Manager 7.1(5A) Cisco Unified Communications Manager 7.1(5)Su1a Cisco Unified Communications Manager 7.1(5)Su1 Cisco Unified Communications Manager 7.1(5) Cisco Unified Communications Manager 7.1(3b)su2 Cisco Unified Communications Manager 7.1(3b)su1 Cisco Unified Communications Manager 7.1(3B) Cisco Unified Communications Manager 7.1(3A)Su1a Cisco Unified Communications Manager 7.1(3a)su1 Cisco Unified Communications Manager 7.1(3A) Cisco Unified Communications Manager 7.1(3) |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager CVE-2013-3434 Local Privilege Escalation Vulnerability
Cisco Unified Communications Manager is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges. Successful exploits will result in the complete compromise of affected computers.
This issue is being tracked by Cisco Bug ID CSCui02242.
Cisco Unified Communications Manager is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges. Successful exploits will result in the complete compromise of affected computers.
This issue is being tracked by Cisco Bug ID CSCui02242.
Exploit / POC
Cisco Unified Communications Manager CVE-2013-3434 Local Privilege Escalation Vulnerability
The researcher who discovered this issue has developed exploit code to demonstrate it.
The researcher who discovered this issue has developed exploit code to demonstrate it.
Solution / Fix
Cisco Unified Communications Manager CVE-2013-3434 Local Privilege Escalation Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified Communications Manager CVE-2013-3434 Local Privilege Escalation Vulnerability
References:
References:
- Cisco Homepage (Cisco )