CVE-2013-7030
Cisco Unified Communications Manager - TFTP Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue
EN DISPUTA ** ** El servicio TFTP en Cisco Unified Communications Manager (también conocido como CUCM o Unified CM) permite a atacantes remotos obtener información sensible de un teléfono a través de una operación RRQ, como lo demuestra el descubrimiento de un campo UseUserCredential texto plano en un fichero SPDefault.cnf.xml . NOTA: el vendedor , discute la importancia de este informe, afirmando que se trata de un comportamiento predeterminado se esperaba, y que en la documentación del producto se describe el uso de la opción TFTP cifrados Config para tratar este asunto.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2013-12-09 CVE Reserved
- 2013-12-12 CVE Published
- 2013-12-12 First Exploit
- 2024-06-29 EPSS Updated
- 2024-10-29 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://osvdb.org/100916 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/89649 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30237 | 2013-12-12 | |
http://www.exploit-db.com/exploits/30237 | 2024-10-29 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unified Communications Manager Search vendor "Cisco" for product "Unified Communications Manager" | * | - |
Affected
|