100916vdb entry
http://osvdb.org/100916 CVE-2013-7030
HIGH
Cisco Unified Communications Manager - TFTP Service
Record summary
CVE-2013-7030 has a selected CVSS score of 7.3 (high); EIP currently links 1 catalogued exploit.
Description
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 29, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
cisco_unified_communications_managerBrowse cisco / cisco_unified_communications_managerDefault status: unknown | CVE List | Version range not supplied | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCisco Unified Communications Manager - TFTP ServiceExploitDB exploitby daniel svartmanNot analyzed1 file
References
430237exploit
http://www.exploit-db.com/exploits/30237 cisco-ucm-tftp-info-disc(89649)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/89649 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-7030