PT-2008-3579 · Cisco · Cisco Unified Communications Manager
Published
2008-06-26
·
Updated
2019-07-31
·
CVE-2008-2062
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Communications Manager versions prior to 4.2(3)SR4
Cisco Unified Communications Manager versions 4.3 prior to 4.3(2)SR1
Description
The issue allows remote attackers to bypass authentication and obtain cluster configuration information and statistics via a direct TCP connection to the service port.
Recommendations
For versions prior to 4.2(3)SR4, update to version 4.2(3)SR4 or later.
For versions 4.3 prior to 4.3(2)SR1, update to version 4.3(2)SR1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Unified Communications Manager