CVE-2021-1406

MEDIUM

Cisco Unified Communications Manager - Information Disclosure

Title source: rule
STIX 2.1

Description

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper inclusion of sensitive information in downloadable files. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to obtain hashed credentials of system users. To exploit this vulnerability an attacker would need to have valid user credentials with elevated privileges.

Scores

CVSS v3 4.9
EPSS 0.0018
EPSS Percentile 39.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-538
Status published
Products (26)
cisco/unified_communications_manager 10.5\(2\) (2 CPE variants)
cisco/unified_communications_manager 10.5\(2\)su1 (2 CPE variants)
cisco/unified_communications_manager 10.5\(2\)su2 (2 CPE variants)
cisco/unified_communications_manager 10.5\(2\)su2a (2 CPE variants)
cisco/unified_communications_manager 10.5\(2\)su3 (2 CPE variants)
cisco/unified_communications_manager 10.5\(2\)su3a (2 CPE variants)
cisco/unified_communications_manager 10.5\(2\)su4 (2 CPE variants)
cisco/unified_communications_manager 10.5\(2\)su4a (2 CPE variants)
cisco/unified_communications_manager 10.5\(2\)su5
cisco/unified_communications_manager 10.5\(2\)su6 (2 CPE variants)
... and 16 more
Published Apr 08, 2021
Tracked Since Feb 18, 2026