CVE-2013-3404
published 2013-07-18CVE-2013-3404: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.13%
63.1th percentile
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted credentials by leveraging metadata, aka Bug ID CSCuh01051.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Remote Blind SQL Injection Vulnerability
vendor_cisco·2013-07-17·CVSS 7.5
CVE-2013-3404 [HIGH] CWE-89 Cisco Unified Communications Manager Remote Blind SQL Injection Vulnerability
Cisco Unified Communications Manager Remote Blind SQL Injection Vulnerability
Cisco Unified Communication Manager (Unified CM) contains a vulnerability that could allow an unauthenticated, remote attacker to execute a blind Structured Query Language (SQL) injection.
The vulnerability is due to improper validation of user-supplied requests by the Cisco Unified CM. An attacker could exploit this vulnerability by injecting SQL commands. An exploit could allow the attacker to leverage metadata to recreate encrypted information within the database. This metadata could be used to reconstruct encrypted credentials.
Proof-of-concept code that demonstrates an exploit of this vulnerability is publicly available.
Cisco has confirmed the vulnerability in a security advisory and has released a temp
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco·2013-07-17·CVSS 6.8
CVE-2013-3402 [MEDIUM] CWE-20 Multiple Vulnerabilities in Cisco Unified Communications Manager
Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) contains multiple vulnerabilities that could be used together to allow an unauthenticated, remote attacker to gather user credentials, escalate privileges, and execute commands to gain full control of the vulnerable system. A successful attack could allow an unauthenticated attacker to access, create or modify information in Cisco Unified CM.
On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted in a complete
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco
CVE-2013-3404 Multiple Vulnerabilities in Cisco Unified Communications Manager
CVE-2013-3404: Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) contains multiple vulnerabilities that could be used together to allow an unauthenticated, remote attacker to gather user credentials, escalate privileges, and execute commands to gain full control of the vulnerable system. A successful attack could allow an unauthenticated attacker to access, create or modify information in Cisco Unified CM. On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted i
GHSA
GHSA-f66v-2h8q-jpfq: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7
ghsa_unreviewed·2022-05-17
CVE-2013-3404 [HIGH] CWE-89 GHSA-f66v-2h8q-jpfq: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted credentials by leveraging metadata, aka Bug ID CSCuh01051.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-07-18
Published