CVE-2009-0632
published 2009-03-12CVE-2009-0632: The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before…
PriorityP347critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
3.02%
86.1th percentile
The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability
vendor_cisco·2009-03-11·CVSS 9.0
CVE-2009-0632 [CRITICAL] CWE-264 Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability
Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability
Cisco Unified Communications Manager, formerly CallManager, contains a
privilege escalation vulnerability in the IP Phone Personal Address Book (PAB)
Synchronizer feature that may allow an attacker to gain complete administrative
access to a vulnerable Cisco Unified Communications Manager system. If Cisco
Unified Communications Manager is integrated with an external directory
service, it may be possible for an attacker to leverage the privilege
escalation vulnerability to gain access to additional systems configured to use
the directory service for authentication.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerabil
Cisco
Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability
vendor_cisco
CVE-2009-0632 Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability
CVE-2009-0632: Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability
Cisco Unified Communications Manager, formerly CallManager, contains a privilege escalation vulnerability in the IP Phone Personal Address Book (PAB) Synchronizer feature that may allow an attacker to gain complete administrative access to a vulnerable Cisco Unified Communications Manager system. If Cisco Unified Communications Manager is integrated with an external directory service, it may be possible for an attacker to leverage the privilege escalation vulnerability to gain access to additional systems configured to use the directory service for authentication. Cisco has released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs
GHSA
GHSA-cfrx-jj8w-q779: The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4
ghsa_unreviewed·2022-05-02
CVE-2009-0632 [HIGH] GHSA-cfrx-jj8w-q779: The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4
The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/52589http://secunia.com/advisories/34238http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080a86434.htmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a8643c.shtmlhttp://www.securityfocus.com/bid/34082http://www.securitytracker.com/id?1021839http://www.vupen.com/english/advisories/2009/0675https://exchange.xforce.ibmcloud.com/vulnerabilities/49196http://osvdb.org/52589http://secunia.com/advisories/34238http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080a86434.htmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a8643c.shtmlhttp://www.securityfocus.com/bid/34082http://www.securitytracker.com/id?1021839http://www.vupen.com/english/advisories/2009/0675https://exchange.xforce.ibmcloud.com/vulnerabilities/49196
2009-03-12
Published