CVE-2008-2730
published 2008-06-26CVE-2008-2730: The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.69%
74.7th percentile
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsj90843.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
vendor_cisco·2008-06-25·CVSS 7.8
CVE-2008-2061 [HIGH] CWE-200 Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly Cisco
CallManager, contains a denial of service (DoS) vulnerability in the Computer
Telephony Integration (CTI) Manager service that may cause an interruption in
voice services and an authentication bypass vulnerability in the Real-Time
Information Server (RIS) Data Collector that may expose information that is
useful for reconnaissance.
Cisco has released software updates that address these vulnerabilities. There are no workarounds for these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080625-cucm.
Cisco
Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
vendor_cisco
CVE-2008-2730 Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
CVE-2008-2730: Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Computer Telephony Integration (CTI) Manager service that may cause an interruption in voice services and an authentication bypass vulnerability in the Real-Time Information Server (RIS) Data Collector that may expose information that is useful for reconnaissance. Cisco has released software updates that address these vulnerabilities. There are no
CWE: CWE-200, CWE-399, CWE-200, CWE-399
Bug IDs: CSCso75027, CSCsq35151, CSCsj90843, CSCso75027, CSCsq35151
GHSA
GHSA-4fwq-hhhj-mfgx: The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2008-2730 [MEDIUM] CWE-287 GHSA-4fwq-hhhj-mfgx: The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsj90843.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/30848http://www.cisco.com/en/US/products/products_security_advisory09186a00809b9011.shtmlhttp://www.securityfocus.com/bid/29935http://www.securitytracker.com/id?1020361http://www.vupen.com/english/advisories/2008/1933/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43355http://secunia.com/advisories/30848http://www.cisco.com/en/US/products/products_security_advisory09186a00809b9011.shtmlhttp://www.securityfocus.com/bid/29935http://www.securitytracker.com/id?1020361http://www.vupen.com/english/advisories/2008/1933/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43355
2008-06-26
Published