Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-7030

Опубликовано: 12 дек. 2013
Источник: nvd
CVSS3: 7.3
CVSS2: 5
EPSS Средний

Описание

The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.16953
Средний

7.3 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

CVSS3: 7.3
github
больше 3 лет назад

** DISPUTED ** The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue.

EPSS

Процентиль: 95%
0.16953
Средний

7.3 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-310