| PROBLEM: | Cisco Unified Communications Manager (CUCM), formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Computer Telephony Integration (CTI) Manager service that may cause an interruption in voice services and an authentication bypass vulnerability inthe Real-Time Information Server (RIS) Data Collector that may expose information that is useful for reconnaissance. |
| PLATFORM: | Cisco Unified CallManager 4.1 versions Cisco Unified Communications Manager 4.2 versions prior to 4.2(3)SR4 Cisco Unified Communications Manager 4.3 versions prior to 4.3(2)SR1 Cisco Unified Communications Manager 5.x versions prior to 5.1(3c) Cisco Unified Communications Manager 6.x versions prior to 6.1(2) |
| DAMAGE: | DoS and authentication bypass. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is LOW. Successful exploitation of the vulnerabilities in this advisory may result in the interruption of voice services or disclosure of information useful for reconnaissance. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
7.8 6.4 (AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-330.shtml |
| ORIGINAL BULLETIN: | http://www.cisco.com/en/US/products/products_security_advisory09186a00809b9011.shtml |
| CVE: | CVE-2008-2061 CVE-2008-2062 CVE-2008-2730 |
[***** Start Cisco Security Advisory Document ID: 107378 *****]
Summary
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
Cisco Security Procedures
Cisco Unified Communications Manager (CUCM), formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Computer Telephony Integration (CTI) Manager service that may cause an interruption in voice services and an authentication bypass vulnerability in the Real-Time Information Server (RIS) Data Collector that may expose information that is useful for reconnaissance.
Cisco has released free software updates that address these vulnerabilities. There are no workarounds for these vulnerabilities.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20080625-cucm.shtml.
[Expand all sections] [Collapse all sections]
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
[***** End Cisco Security Advisory Document ID: 107378 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org