Vulnslist

find the latest Cisco vulnerabilities

CVE-2018-0267

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker to view sensitive information that should have been restricted. Cisco Bug IDs: CSCvf22116.

SeverityMEDIUM
CVSS6.5
CWECWE-200
KEV
Published
Modified

Related Products

Product Advisory
Cisco Nexus Dashboard cisco-sa-20180418-ucm1
Cisco Application Centric Infrastructure Virtual Edge cisco-sa-20180418-ucm1
Cisco Unified Communications Manager cisco-sa-20180418-ucm1