Showing 1 vulnerability on this page for cisco_unified_communications_manager

Signals CISA KEV Ransomware Nuclei
Cisco vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Cisco Unified Communications Manager - TFTP Service

The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this is

CWE-310Dec 12, 2013
CVSS7.3v3.1EPSS5.17%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX