CVE-2008-1154
published 2008-04-04CVE-2008-1154: The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x…
PriorityP358critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.14%
91.4th percentile
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | emergency_responder | — | — |
| cisco | mobility_manager | — | — |
| cisco | unified_communications_disaster_recovery_framework | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_presence | — | — |
| cisco | unified_presence | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability
vendor_cisco·2008-04-03·CVSS 10.0
CVE-2008-1154 [CRITICAL] CWE-94 Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability
Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability
Several products in the Cisco Unified Communications family of products
contain a command execution vulnerability in the Disaster Recovery Framework
(DRF) feature. A remote, unauthenticated user could exploit this vulnerability
to execute arbitrary commands that may allow full administrative access to
affected systems. There is a workaround for this vulnerability.
Cisco has released software updates that address this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080403-drf.
Cisco
Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability
vendor_cisco
CVE-2008-1154 Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability
CVE-2008-1154: Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability
Several products in the Cisco Unified Communications family of products contain a command execution vulnerability in the Disaster Recovery Framework (DRF) feature. A remote, unauthenticated user could exploit this vulnerability to execute arbitrary commands that may allow full administrative access to affected systems. There is a workaround for this vulnerability. Cisco has released software updates that address this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080403-drf .
CWE: CWE-94, CWE-94
Bug IDs: CSCso53771, CSCso53771, CSCso53771
GHSA
GHSA-x77v-m6g8-v8pp: The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2008-1154 [HIGH] CWE-287 GHSA-x77v-m6g8-v8pp: The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/29670http://securitytracker.com/id?1019768http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtmlhttp://www.securityfocus.com/bid/28591http://www.vupen.com/english/advisories/2008/1093https://exchange.xforce.ibmcloud.com/vulnerabilities/41632http://secunia.com/advisories/29670http://securitytracker.com/id?1019768http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtmlhttp://www.securityfocus.com/bid/28591http://www.vupen.com/english/advisories/2008/1093https://exchange.xforce.ibmcloud.com/vulnerabilities/41632
2008-04-04
Published