| PROBLEM: | Several products int he Cisco Unified Communications family of products contain a command execution vulnerability in the Disaster Recovery Framework (DRF) feature. |
| PLATFORM: |
Cisco Unified Communications Manager (CUCM) 5.x and 6.x Cisco Unified Communications Manager Business Edition Cisco Unified Precense 1.x and 6.x Cisco Emergency Responder 2.x Cisco Mobility Manager 2.x |
| DAMAGE: | Execution of arbitrary commands. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. A remote, unauthenticated user could exploit this vulnerability to execute arbitrary commands that may allow full administration access to affected systems. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
10.0 8.3 (AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-249.shtml |
| ORIGINAL BULLETIN: | http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml |
| CVE: | CVE-2008-1154 |
[***** Start Cisco Security Advisory Document ID: 101129 *****]
Summary
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
Cisco Security Procedures
Several products in the Cisco Unified Communications family of products contain a command execution vulnerability in the Disaster Recovery Framework (DRF) feature. A remote, unauthenticated user could exploit this vulnerability to execute arbitrary commands that may allow full administrative access to affected systems. There is a workaround for this vulnerability.
Cisco has released free software updates that address this vulnerability.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20080403-drf.shtml.
[Expand all sections] [Collapse all sections]
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
[***** End Cisco Security Advisory Document ID: 101129 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org