Vulnslist

find the latest Cisco vulnerabilities

Cisco Unity Connection Information Disclosure Vulnerability

Cisco-SA-20141105-CVE-2014-7988 · Medium · Published · Updated

A vulnerability in the Unified Messaging Service (UMS) of Cisco Unity Connection, could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to the inclusion of sensitive information in the logs. An attacker could exploit this vulnerability by viewing the sensitive information stored in the vulnerable logs. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must authenticate to a targeted device. This access requirement may reduce the likelihood of a successful exploit.

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to allow only privileged users to access administration or management systems.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-7988
Cisco Bug IDsCSCur06493
CVSS ScoreBase 6.8
Base 6.8 AV:N/AC:L/Au:S/C:C/I:N/A:N/E:F/RL:OF/RC:C
Product Names From Source
Cisco Unity Connection

Related Products

Product CVE Evidence
Cisco Unity CVE-2014-7988 Cisco OpenVuln
Cisco Unity Connection CVE-2014-7988 Cisco OpenVuln