CVE-2008-3814

Cisco Unity <4.2.1-5.0.1-7.0.2 - Auth Bypass

Title source: llm

Description

Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once.

Scores

EPSS 0.0048
EPSS Percentile 64.8%

Classification

CWE
CWE-287
Status draft

Affected Products (14)

cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity
cisco/unity

Timeline

Published Oct 08, 2008
Tracked Since Feb 18, 2026