Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once.
2008-10-08T22:00:01.730
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | unity | 4.0 | Yes |
Application | cisco | unity | 4.0\(1\) | Yes |
Application | cisco | unity | 4.0\(2\) | Yes |
Application | cisco | unity | 4.0\(3\) | Yes |
Application | cisco | unity | 4.0\(3\) | Yes |
Application | cisco | unity | 4.0\(4\) | Yes |
Application | cisco | unity | 4.0\(4\) | Yes |
Application | cisco | unity | 4.0\(5\) | Yes |
Application | cisco | unity | 4.1\(1\) | Yes |
Application | cisco | unity | 4.2\(1\) | Yes |
Application | cisco | unity | 5.0 | Yes |
Application | cisco | unity | 5.0\(1\) | Yes |
Application | cisco | unity | 7.0 | Yes |
Application | cisco | unity | 7.0\(2\) | Yes |