// For flags

CVE-2021-1226

Cisco Unified Communications Products Information Disclosure Vulnerability

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.

Una vulnerabilidad en el componente de registro de auditoría de Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & amp; Presence Service, Cisco Unity Connection, Cisco Emergency Responder y Cisco Prime License Manager, podría permitir a un atacante remoto autenticado visualizar información confidencial en texto sin cifrar en un sistema afectado. La vulnerabilidad es debido al almacenamiento de determinadas credenciales no cifradas. Un atacante podría explotar esta vulnerabilidad accediendo a los registros de auditoría en un sistema afectado y obteniendo credenciales a las que normalmente no tiene acceso. Una explotación con éxito podría permitir al atacante usar esas credenciales para detectar y administrar dispositivos de red.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2020-11-13 CVE Reserved
  • 2021-01-13 CVE Published
  • 2024-09-30 EPSS Updated
  • 2024-11-12 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-532: Insertion of Sensitive Information into Log File
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Emergency Responder
Search vendor "Cisco" for product "Emergency Responder"
>= 12.5\(1\) < 12.5\(1\)su3
Search vendor "Cisco" for product "Emergency Responder" and version " >= 12.5\(1\) < 12.5\(1\)su3"
-
Affected
Cisco
Search vendor "Cisco"
Emergency Responder
Search vendor "Cisco" for product "Emergency Responder"
10.5\(2\)
Search vendor "Cisco" for product "Emergency Responder" and version "10.5\(2\)"
-
Affected
Cisco
Search vendor "Cisco"
Emergency Responder
Search vendor "Cisco" for product "Emergency Responder"
11.5\(1\)
Search vendor "Cisco" for product "Emergency Responder" and version "11.5\(1\)"
-
Affected
Cisco
Search vendor "Cisco"
Emergency Responder
Search vendor "Cisco" for product "Emergency Responder"
12.0\(1\)
Search vendor "Cisco" for product "Emergency Responder" and version "12.0\(1\)"
-
Affected
Cisco
Search vendor "Cisco"
Prime License Manager
Search vendor "Cisco" for product "Prime License Manager"
>= 11.5\(1\) < 11.5\(1\)su9
Search vendor "Cisco" for product "Prime License Manager" and version " >= 11.5\(1\) < 11.5\(1\)su9"
-
Affected
Cisco
Search vendor "Cisco"
Prime License Manager
Search vendor "Cisco" for product "Prime License Manager"
10.5\(2\)
Search vendor "Cisco" for product "Prime License Manager" and version "10.5\(2\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
>= 11.5\(1\) < 11.5\(1\)su9
Search vendor "Cisco" for product "Unified Communications Manager" and version " >= 11.5\(1\) < 11.5\(1\)su9"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
>= 11.5\(1\) < 11.5\(1\)su9
Search vendor "Cisco" for product "Unified Communications Manager" and version " >= 11.5\(1\) < 11.5\(1\)su9"
session_management
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
10.5\(2\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "10.5\(2\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager
Search vendor "Cisco" for product "Unified Communications Manager"
10.5\(2\)
Search vendor "Cisco" for product "Unified Communications Manager" and version "10.5\(2\)"
session_management
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager Im \& Presence Service
Search vendor "Cisco" for product "Unified Communications Manager Im \& Presence Service"
>= 11.5\(1\) < 11.5\(1\)su9
Search vendor "Cisco" for product "Unified Communications Manager Im \& Presence Service" and version " >= 11.5\(1\) < 11.5\(1\)su9"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager Im \& Presence Service
Search vendor "Cisco" for product "Unified Communications Manager Im \& Presence Service"
>= 12.5\(1\) < 12.5\(1\)su3
Search vendor "Cisco" for product "Unified Communications Manager Im \& Presence Service" and version " >= 12.5\(1\) < 12.5\(1\)su3"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager Im \& Presence Service
Search vendor "Cisco" for product "Unified Communications Manager Im \& Presence Service"
10.5\(2\)
Search vendor "Cisco" for product "Unified Communications Manager Im \& Presence Service" and version "10.5\(2\)"
-
Affected
Cisco
Search vendor "Cisco"
Unified Communications Manager Im \& Presence Service
Search vendor "Cisco" for product "Unified Communications Manager Im \& Presence Service"
12.0\(1\)
Search vendor "Cisco" for product "Unified Communications Manager Im \& Presence Service" and version "12.0\(1\)"
-
Affected
Cisco
Search vendor "Cisco"
Unity Connection
Search vendor "Cisco" for product "Unity Connection"
>= 11.5\(1\) < 11.5\(1\)su9
Search vendor "Cisco" for product "Unity Connection" and version " >= 11.5\(1\) < 11.5\(1\)su9"
-
Affected
Cisco
Search vendor "Cisco"
Unity Connection
Search vendor "Cisco" for product "Unity Connection"
>= 12.0\(1\) < 12.0\(1\)su4
Search vendor "Cisco" for product "Unity Connection" and version " >= 12.0\(1\) < 12.0\(1\)su4"
-
Affected
Cisco
Search vendor "Cisco"
Unity Connection
Search vendor "Cisco" for product "Unity Connection"
>= 12.5\(1\) < 12.5\(1\)su3
Search vendor "Cisco" for product "Unity Connection" and version " >= 12.5\(1\) < 12.5\(1\)su3"
-
Affected
Cisco
Search vendor "Cisco"
Unity Connection
Search vendor "Cisco" for product "Unity Connection"
10.5\(2\)
Search vendor "Cisco" for product "Unity Connection" and version "10.5\(2\)"
-
Affected