CVE-2013-6978
published 2013-12-21CVE-2013-6978: The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain…
PriorityP417medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.09%
79.7th percentile
The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extraneous information" in HTML source code, aka Bug ID CSCuj39249.
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 9.1\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wg9v-ffh8-2wwj: The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9
ghsa_unreviewed·2022-05-17
CVE-2013-6978 [MEDIUM] CWE-200 GHSA-wg9v-ffh8-2wwj: The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9
The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extraneous information" in HTML source code, aka Bug ID CSCuj39249.
Cisco
Cisco Unified Communications Manager Sensitive Information Disclosure Vulnerability
vendor_cisco·2013-12-18·CVSS 4.0
CVE-2013-6978 [MEDIUM] CWE-200 Cisco Unified Communications Manager Sensitive Information Disclosure Vulnerability
Cisco Unified Communications Manager Sensitive Information Disclosure Vulnerability
A vulnerability in the disaster recovery system (DRS) of Cisco Unified Communications Manager (UCM) could allow an authenticated, remote attacker to acquire sensitive information about DRS-related devices.
The vulnerability is due to extraneous information included in the web page. An attacker could exploit this vulnerability by accessing the affected web page and extracting the sensitive information. An exploit could allow the attacker to gain sensitive information about devices configured for DRS use.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement de
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/101162http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6978http://tools.cisco.com/security/center/viewAlert.x?alertId=32219http://www.securityfocus.com/bid/64421http://www.securitytracker.com/id/1029520https://exchange.xforce.ibmcloud.com/vulnerabilities/89834http://osvdb.org/101162http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6978http://tools.cisco.com/security/center/viewAlert.x?alertId=32219http://www.securityfocus.com/bid/64421http://www.securitytracker.com/id/1029520https://exchange.xforce.ibmcloud.com/vulnerabilities/89834
2013-12-21
Published