CVE-2013-3402
published 2013-07-18CVE-2013-3402: An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands…
PriorityP339medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.00%
78.7th percentile
An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8m88-59vr-3wh9: An unspecified function in Cisco Unified Communications Manager (CUCM) 7
ghsa_unreviewed·2022-05-17
CVE-2013-3402 [MEDIUM] CWE-94 GHSA-8m88-59vr-3wh9: An unspecified function in Cisco Unified Communications Manager (CUCM) 7
An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440.
Cisco
Cisco Unified Communications Manager Command Injection Vulnerability
vendor_cisco·2013-07-17·CVSS 6.5
CVE-2013-3402 [MEDIUM] CWE-20 Cisco Unified Communications Manager Command Injection Vulnerability
Cisco Unified Communications Manager Command Injection Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM) could allow an authenticated, remote attacker to execute commands on the underlying operating system with the privileges of the database user.
The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by submitting malicious input to the affected function.
Proof-of-concept code that demonstrates an exploit of this vulnerability is publicly available.
Cisco has confirmed the vulnerability in a security advisory; however, software updates are not available.
To exploit this vulnerability, an attacker requires authenticated access to the targeted system. Authenticated access may require the att
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco·2013-07-17·CVSS 6.8
CVE-2013-3402 [MEDIUM] CWE-20 Multiple Vulnerabilities in Cisco Unified Communications Manager
Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) contains multiple vulnerabilities that could be used together to allow an unauthenticated, remote attacker to gather user credentials, escalate privileges, and execute commands to gain full control of the vulnerable system. A successful attack could allow an unauthenticated attacker to access, create or modify information in Cisco Unified CM.
On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted in a complete
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco
CVE-2013-3402 Multiple Vulnerabilities in Cisco Unified Communications Manager
CVE-2013-3402: Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) contains multiple vulnerabilities that could be used together to allow an unauthenticated, remote attacker to gather user credentials, escalate privileges, and execute commands to gain full control of the vulnerable system. A successful attack could allow an unauthenticated attacker to access, create or modify information in Cisco Unified CM. On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-07-18
Published