9
CVSSv2

CVE-2009-0632

Published: 12/03/2009 Updated: 17/08/2017
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 prior to 4.2(3)SR4b, 4.3 prior to 4.3(2)SR1b, 5.x prior to 5.1(3e), 6.x prior to 6.1(3), and 7.0 prior to 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote malicious users to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x up to and including 7.x.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 4.1

cisco unified communications manager 4.3\\(2\\)sr1

cisco unified communications manager 4.3\\(2\\)

cisco unified communications manager 5.1\\(1\\)

cisco unified communications manager 5.1\\(3d\\)

cisco unified communications manager 6.1\\(1\\)

cisco unified communications manager 6.1\\(2\\)

cisco unified communications manager 4.2\\(3\\)sr1

cisco unified communications manager 4.2\\(3\\)sr4

cisco unified communications manager 5.1\\(3c\\)

cisco unified communications manager 5.1\\(3a\\)

cisco unified communications manager 6.0\\(1a\\)

cisco unified communications manager 6.0\\(1\\)

cisco unified communications manager 7.0

cisco unified communications manager 7.0\\(1\\)

cisco unified communications manager 4.2\\(3\\)sr3

cisco unified communications manager 4.2\\(3\\)sr2b

cisco unified communications manager 5.1\\(3\\)

cisco unified communications manager 5.1\\(2b\\)

cisco unified communications manager 5.1\\(2\\)

cisco unified communications manager 6.1

cisco unified communications manager 6.1\\(2\\)su1

cisco unified communications manager 4.2

cisco unified communications manager 4.3

cisco unified communications manager 4.3\\(1\\)sr.1

cisco unified communications manager 5.0

cisco unified communications manager 5.1\\(2a\\)

cisco unified communications manager 6.0

cisco unified communications manager 6.1\\(3\\)

cisco unified communications manager 6.1\\(1a\\)