CVE-2008-3814
Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify…
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- cisco/unity
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/32187Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a0d85f.shtmlPatch, Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_response09186a0080a0d861.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/31638
- http://www.securityfocus.com/bid/31642
- http://www.securitytracker.com/id?1021011
- http://www.voipshield.com/research-details.php?id=126
- http://www.vupen.com/english/advisories/2008/2771Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45741
- http://secunia.com/advisories/32187Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a0d85f.shtmlPatch, Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_response09186a0080a0d861.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/31638
- http://www.securityfocus.com/bid/31642
- http://www.securitytracker.com/id?1021011
- http://www.voipshield.com/research-details.php?id=126
- http://www.vupen.com/english/advisories/2008/2771Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45741
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.