Record summary

CVE-2013-7030 has a selected CVSS score of 7.3 (high); EIP currently links 1 catalogued exploit.

Description

The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 29, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

cisco_unified_communications_manager

Browse cisco / cisco_unified_communications_manager

Default status: unknown

CVE ListVersion range not suppliedaffected

Proofs of concept

1

Catalogued exploits

ExploitDBCisco Unified Communications Manager - TFTP ServiceExploitDB exploitby daniel svartmanNot analyzed1 file
ExploitDB

PoC details

References

4