QID 316945
Date Published: 2021-04-21
QID 316945: Cisco Unified Communications Manager Information Disclosure Vulnerability(cisco-sa-cucm-inf-disc-wCxZNjL2)
A vulnerability in Cisco Unified Communications Manager (Unified CM) and
Cisco Unified Communications Manager Session Management Edition (Unified CM SME)
could allow an authenticated, remote attacker to access sensitive information on an affected device.
Affected Products
Following releases of Cisco Unified CM and Cisco Unified CM SME:
10.5(2), all releases
11.5(1), all releases
12.0(1), all releases
12.5(1), all releases
QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.
A successful exploit could allow the attacker to obtain hashed credentials of system users.
To exploit this vulnerability an attacker would need to have valid user credentials with elevated privileges.
Customers are advised to refer to cisco-sa-cucm-inf-disc-wCxZNjL2 for more information.
- cisco-sa-cucm-inf-disc-wCxZNjL2 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-inf-disc-wCxZNjL2
CVEs related to QID 316945
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-cucm-inf-disc-wCxZNjL2 |
|