CVE-2007-3776
published 2007-07-15CVE-2007-3776: Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via…
PriorityP419medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.49%
71.4th percentile
Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager_and_presence_server_unauthorized_access | — | — |
| cisco | unified_presence_server | — | — |
| cisco | unified_presence_server | — | — |
| cisco | unified_presence_server | — | — |
| cisco | unified_presence_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerabilities
vendor_cisco·2007-07-11·CVSS 7.0
CVE-2007-3775 [HIGH] CWE-200 Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerabilities
Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly CallManager, and
Cisco Unified Presence Server (CUPS) contain two vulnerabilities that could
allow an unauthorized administrator to activate and terminate CUCM / CUPS
system services and access SNMP configuration information. This may
respectively result in a denial of service (DoS) condition affecting CUCM/CUPS
cluster systems and the disclosure of sensitive SNMP details, including
community strings.
There are no workarounds for these vulnerabilities.
Cisco has made free software available to address these vulnerabilities
for affected customers.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityA
Cisco
Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerabilities
vendor_cisco
CVE-2007-3776 Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerabilities
CVE-2007-3776: Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly CallManager, and Cisco Unified Presence Server (CUPS) contain two vulnerabilities that could allow an unauthorized administrator to activate and terminate CUCM / CUPS system services and access SNMP configuration information. This may respectively result in a denial of service (DoS) condition affecting CUCM/CUPS cluster systems and the disclosure of sensitive SNMP
CWE: CWE-200, CWE-264, CWE-200, CWE-264
Bug IDs: CSCsj09859, CSCsj19985, CSCsj20668, CSCsj25962, CSCsj09859
GHSA
GHSA-2f3q-68v6-f6wq: Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive inform
ghsa_unreviewed·2022-05-01
CVE-2007-3776 [MEDIUM] GHSA-2f3q-68v6-f6wq: Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive inform
Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/36124http://secunia.com/advisories/26039http://securitytracker.com/id?1018368http://www.cisco.com/warp/public/707/cisco-sa-20070711-voip.shtmlhttp://www.securityfocus.com/bid/24867http://www.vupen.com/english/advisories/2007/2511https://exchange.xforce.ibmcloud.com/vulnerabilities/35344http://osvdb.org/36124http://secunia.com/advisories/26039http://securitytracker.com/id?1018368http://www.cisco.com/warp/public/707/cisco-sa-20070711-voip.shtmlhttp://www.securityfocus.com/bid/24867http://www.vupen.com/english/advisories/2007/2511https://exchange.xforce.ibmcloud.com/vulnerabilities/35344
2007-07-15
Published