QID 317205

Date Published: 2022-07-11

QID 317205: Cisco Unified Communications Products Timing Attack Vulnerability (cisco-sa-ucm-timing-JVbHECOK)

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack.

Affected Products
Unified CM
Unified CM SME
Unity Connection
QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.

A successful exploit could allow the attacker to determine a sensitive system password.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ucm-timing-JVbHECOK for more information.

    CVEs related to QID 317205

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ucm-timing-JVbHECOK URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucm-timing-JVbHECOK