A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exploit this vulnerability by observing the time it takes the system to respond to various queries. A successful exploit could allow the attacker to determine a sensitive system password.
2022-07-06T21:15:11.387
2024-11-21T06:43:28.820
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | unified_communications_manager | < 12.5\(1\)su6 | Yes |
Application | cisco | unified_communications_manager | < 12.5\(1\)su6 | Yes |
Application | cisco | unified_communications_manager | < 14su1 | Yes |
Application | cisco | unified_communications_manager | < 14su1 | Yes |
Application | cisco | unity_connection | < 12.5\(1\)su6 | Yes |
Application | cisco | unity_connection | < 14su1 | Yes |