// For flags

CVE-2009-0632

 

Severity Score

9.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.

La funcionalidad IP Phone Personal Address Book (PAB) Synchronizer en Cisco Unified Communications Manager (también conocido como CUCM, formalmente CallManager) v4.1, v4.2 anteriores v4.2(3)SR4b, v4.3 anteriores v4.3(2)SR1b, v5.x anteriores v5.1(3e), v6.x anteriores v6.1(3), y v7.0 anteriores v7.0(2) envía credenciales de cuentas privilegiadas del servicio directorio a el cliente en texto plano, lo que permite a los atacantes remotos modificar la configuración CUCM y desarrollar otros acciones privilegiadas interceptando estas credenciales, y usándola en peticiones no relativas a las tareas de sincronización establecidas, como se ha demostrado a través de (1) credenciales de la cuenta DC Directory en CUCM v4.x y (2) credenciales de cuenta TabSyncSysUser en CUCM v5.x hasta v7.x.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-02-18 CVE Reserved
  • 2009-03-11 CVE Published
  • 2023-04-30 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.1
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.1"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.2
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.2"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.2\(3\)sr1
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.2\(3\)sr1"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.2\(3\)sr2b
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.2\(3\)sr2b"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.2\(3\)sr3
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.2\(3\)sr3"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.2\(3\)sr4
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.2\(3\)sr4"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.3
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.3"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.3\(1\)sr.1
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.3\(1\)sr.1"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.3\(2\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.3\(2\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
4.3\(2\)sr1
Search vendor "Cisco" for product "Unified Communications Manager" and version "4.3\(2\)sr1"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.0
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.0"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.1\(1\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.1\(1\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.1\(2\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.1\(2\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.1\(2a\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.1\(2a\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.1\(2b\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.1\(2b\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.1\(3\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.1\(3\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.1\(3a\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.1\(3a\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.1\(3c\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.1\(3c\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
5.1\(3d\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "5.1\(3d\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.0
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.0"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.0\(1\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.0\(1\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.0\(1a\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.0\(1a\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.1
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.1"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.1\(1\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.1\(1\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.1\(1a\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.1\(1a\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.1\(2\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.1\(2\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.1\(2\)su1
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.1\(2\)su1"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
6.1\(3\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "6.1\(3\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
7.0
Search vendor "Cisco" for product "Unified Communications Manager" and version "7.0"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
7.0\(1\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "7.0\(1\)"
-
Affected