CVE-2013-3434
published 2013-07-18CVE-2013-3434: Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging…
PriorityP419medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.36%
28.3th percentile
Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02242.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8r7x-834x-qfc5: Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7
ghsa_unreviewed·2022-05-17
CVE-2013-3434 [MEDIUM] GHSA-8r7x-834x-qfc5: Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7
Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02242.
Cisco
Cisco Unified Communications Manager Privilege Escalation Vulnerability
vendor_cisco·2013-07-17·CVSS 6.8
CVE-2013-3434 [MEDIUM] CWE-264 Cisco Unified Communications Manager Privilege Escalation Vulnerability
Cisco Unified Communications Manager Privilege Escalation Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM) could allow an authenticated, local attacker to escalate privileges on the system.
The vulnerability is due to improper file permissions on a privileged system binary. An attacker could exploit this vulnerability by modifying a system script, which could allow the attacker to gain complete control of the affected system.
Proof-of-concept code that demonstrates an exploit of this vulnerability is publicly available.
Cisco has confirmed the vulnerability in a security advisory; however, software updates are not available.
To exploit this vulnerability, an attacker needs to authenticate to a targeted device. Authenticated access may require the att
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco·2013-07-17·CVSS 6.8
CVE-2013-3402 [MEDIUM] CWE-20 Multiple Vulnerabilities in Cisco Unified Communications Manager
Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) contains multiple vulnerabilities that could be used together to allow an unauthenticated, remote attacker to gather user credentials, escalate privileges, and execute commands to gain full control of the vulnerable system. A successful attack could allow an unauthenticated attacker to access, create or modify information in Cisco Unified CM.
On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted in a complete
Cisco
Multiple Vulnerabilities in Cisco Unified Communications Manager
vendor_cisco
CVE-2013-3434 Multiple Vulnerabilities in Cisco Unified Communications Manager
CVE-2013-3434: Multiple Vulnerabilities in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) contains multiple vulnerabilities that could be used together to allow an unauthenticated, remote attacker to gather user credentials, escalate privileges, and execute commands to gain full control of the vulnerable system. A successful attack could allow an unauthenticated attacker to access, create or modify information in Cisco Unified CM. On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/95403http://secunia.com/advisories/54249http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130717-cucmhttp://www.securityfocus.com/bid/61296http://osvdb.org/95403http://secunia.com/advisories/54249http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130717-cucmhttp://www.securityfocus.com/bid/61296
2013-07-18
Published