PT-2006-3145 · Cisco · Cisco Unity Express

Publicado

2006-05-04

·

Atualizado

2018-10-30

·

CVE-2006-2166

CVSS v2.0

2.1

Baixa

VetorAV:N/AC:H/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unity Express versions 2.2(2) and earlier
Description The issue affects the HTTP management interface, allowing remote authenticated attackers to reset the password for any user with an expired password when running on any CUE Advanced Integration Module (AIM) or Network Module (NM).
Recommendations For Cisco Unity Express versions 2.2(2) and earlier, consider restricting access to the HTTP management interface until a fix is available. As a temporary workaround, monitor user password expiration and reset processes closely to minimize potential exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2166

Produtos afetados

Cisco Unity Express