QID 730114
Date Published: 2021-06-15
QID 730114: Akkadian Provisioning Manager Multiple Vulnerabilities
The Akkadian Provisioning Manager, which is used as a third-party provisioning tool within Cisco Unified Communications environments,
has three high-severity security vulnerabilities that can be chained together
to enable remote code execution (RCE) with elevated privileges.
CVE-2021-31579: Use of hard-coded credentials
CVE-2021-31580 and CVE-2021-31581: Improper neutralization of special elements used in an OS command
CVE-2021-31582: Exposure of sensitive information to an unauthorized actor.
QID Detection Logic:
Sends a Web request "/pme/database/pme/phinx.yml" to get response
Successful exploitation may lead to remote code execution (RCE) with elevated privileges.
Solution
Akkadian has not come up with any fix.
Vendor References
CVEs related to QID 730114
Software Advisories
| Advisory ID | Software | Component | Link |
|---|