CVE-2013-7030

HIGH

Cisco Unified Communications Manager - Information Disclosure via TFTP RRQ Operation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-7030. PoCs published by daniel svartman.

AI-analyzed exploit summary This script automates the anonymous download of Cisco phone configuration files via TFTP, extracting LDAP credentials and other sensitive information. It leverages predictable MAC address patterns to enumerate and retrieve files.

Description

The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue

Exploits (1)

exploitdb WORKING POC VERIFIED
by daniel svartman · bashlocalhardware
https://www.exploit-db.com/exploits/30237

This script automates the anonymous download of Cisco phone configuration files via TFTP, extracting LDAP credentials and other sensitive information. It leverages predictable MAC address patterns to enumerate and retrieve files.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Cisco Unified IP Phones (TFTP configuration files)
No auth needed
Prerequisites: TFTP server access · Cisco phone MAC address prefix
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/30237/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/89649
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/100916

Scores

CVSS v3 7.3
EPSS 0.0532
EPSS Percentile 91.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-310
Status published
Products (1)
cisco/unified_communications_manager
Published Dec 12, 2013
Tracked Since Feb 18, 2026