PT-2016-1263 · Cisco · Unity Connection+3

Published

2016-02-09

·

Updated

2016-12-06

·

CVE-2016-1319

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager versions 9.1(2.10000.28) through 11.0(1.10000.10) Unified Communications Manager IM & Presence Service version 10.5(2) Unified Contact Center Express version 11.0(1) Unity Connection version 10.5(2)
Description The issue is related to the storage of a cleartext encryption key, allowing local users to obtain sensitive information. The vulnerability can be exploited by an attacker to gain confidential information.
Recommendations For Cisco Unified Communications Manager versions 9.1(2.10000.28) through 11.0(1.10000.10), consider restricting access to sensitive information until a fix is available. For Unified Communications Manager IM & Presence Service version 10.5(2), restrict access to the service to minimize the risk of exploitation. For Unified Contact Center Express version 11.0(1), limit access to confidential data to prevent unauthorized access. For Unity Connection version 10.5(2), avoid using the system until the issue is resolved. As a temporary workaround, consider disabling access to sensitive data for all affected systems until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00535
CVE-2016-1319

Affected Products

Cisco Unified Communications Manager
Cisco Unified Communications Manager Im & Presence Service
Cisco Unified Contact Center Express
Unity Connection