|
 |
|
Cisco Unified Communications Disaster Recovery Framework Command Execution
|
|
|
|
|
Secunia Advisory:
|
SA29670
|
|
|
Release Date:
|
2008-04-04
|
|
Last Update:
|
2008-04-09
|
|
|
Critical:
|

Moderately critical
|
|
Impact:
|
Security Bypass System access
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Cisco Emergency Responder 2.x Cisco Unified Communications Manager 5.x Cisco Unified Communications Manager 6.x Cisco Unified Presence 6.x
|
| | CVE reference: | CVE-2008-1154 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: A vulnerability has been reported in various Cisco products, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to the Disaster Recovery Framework (DRF) Master not performing authentication on requests received over the network. This can be exploited to perform any DRF-related tasks via the DRF Master service (port 4040/TCP).
Successful exploitation allows execution of arbitrary commands.
The vulnerability affects the following products and versions:
* Cisco Unified Communications Manager (CUCM) 5.x and 6.x
* Cisco Unified Communications Manager Business Edition
* Cisco Unified Precense 1.x and 6.x
* Cisco Emergency Responder 2.x
* Cisco Mobility Manager 2.x
Solution: The vendor has issued updates (please see the vendor's advisory for details).
Provided and/or discovered by: VoIPshield Systems
Changelog: 2008-04-09: Added links to "Original Advisory" section.
Original Advisory: Cisco:
http://www.cisco.com/warp/public/707/cisco-sa-20080403-drf.shtml
VoiPshield:
http://www.voipshield.com/component/o...id,30/_cursor,18/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,31/_cursor,19/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,32/_cursor,20/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,33/_cursor,21/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,34/_cursor,22/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,35/_cursor,23/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,36/_cursor,24/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,37/_cursor,25/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,38/_cursor,26/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,39/_cursor,27/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,40/_cursor,28/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,41/_cursor,29/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,42/_cursor,30/_total,44/tableid,1/
http://www.voipshield.com/component/o...id,44/_cursor,31/_total,44/tableid,1/
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
16 Related Secunia Security Advisories, displaying 10
|
|
|
1. Cisco Unified Communications Manager Authentication Bypass and Denial of Service
|
|
2. Cisco Unified Presence SIP Proxy Service Denial of Service
|
|
3. Cisco Unified Communications Manager Multiple Denial of Service
|
|
4. Cisco Unified Communications Manager "key" SQL Injection
|
|
5. Cisco Security Agent Unspecified System Driver Buffer Overflow Vulnerability
|
|
6. Cisco Unified Communications Manager Two Vulnerabilities
|
|
7. Cisco Unified Communications Manager SIP Packet Processing Vulnerability
|
|
8. Cisco Products Java Secure Socket Extension SSL/TLS Request Denial of Service
|
|
9. Cisco Unified Communications Manager Two Vulnerabilities
|
|
10. Cisco Unified Communications Manager and Presence Server Security Bypass
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|