Skip to main content

Cisco Unified Communications Manager Multiple Vulnerabilities

Last Update Date: 27 Aug 2014 Release Date: 13 Aug 2014 3216 Views

RISK: Medium Risk

TYPE: Clients - Im, Chat & Voip

TYPE: Im, Chat & Voip

Multiple vulnerabilities were identified in Cisco Unified Communications Manager. A remote authenticated user can cause denial of service conditions and execute arbitrary commands on the target system.

  1. A remote authenticated user on a registered endpoint can send specially crafted XML data via SIP to cause the target process to crash.
  2. A remote authenticated user can send specially crafted Kerberos single sign-on (SSO) token data to exploit a flaw in the CTIManager module and execute arbitrary commands with elevated privileges.
    Systems with the Cisco CTIManager enabled and configured for single sign-on are affected.

 


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Cisco Unified Communications Manager

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link