CVE-2006-2166

Cisco Unity Express <2.2(2) - Privilege Escalation

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any user with an expired password.

References (7)

Core 7
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19881
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1613
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/25165
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26165
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016015
Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20060501-cue.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17775

Scores

EPSS 0.0162
EPSS Percentile 73.5%

Details

Status published
Products (4)
cisco/unity_express
cisco/unity_express_software 1.1.1
cisco/unity_express_software 2.1.1
cisco/unity_express_software 2.2.2
Published May 04, 2006
Tracked Since Feb 18, 2026