Tuesday, March 17, 2009

Free Rick Solomon One Night In Paris

Privilege escalation in Cisco Unified Communications Manager

Cisco has released an update to Cisco Unified Communications Manager (versions 4.x, 5.x, 6.x and 7.x) that corrects a vulnerability in the synchronization feature of IP Phone Personal Address Book (PAB) that could allow a remote attacker to gain escalated privileges, which could lead to compromise vulnerable systems.

The Cisco Unified Communications solution is a set of products and communications applications
that collects and integrates voice, video and data.

The ruling could be exploited if an attacker intercepts the client credentials sent from Cisco Unified Communications Manager after you have authenticated to the synchronization process.

Cisco, through the usual channels, has made available to customers
solutions to solve the problem.

is advised to consult the table of vulnerable versions and countermeasures
:
http://www.cisco.com/warp/public/707/cisco-sa-20090311-cucmpab.shtml

More Information:

Cisco Security Advisory: Cisco Unified Communications Manager IP Phone Address Book Synchronizer Personal Privilege Escalation Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090311-cucmpab.shtml

Source: www.hispasec.com/unaaldia/ 3794 VoIP2DAY

0 comments:

Post a Comment