CVE-2016-6364
published 2016-08-23CVE-2016-6364: The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restrictions and…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.16%
80.2th percentile
The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified API calls, aka Bug ID CSCux67855.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qj4x-mj6w-4c5v: The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11
ghsa_unreviewed·2022-05-17
CVE-2016-6364 [HIGH] CWE-200 GHSA-qj4x-mj6w-4c5v: The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11
The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified API calls, aka Bug ID CSCux67855.
Cisco
Cisco Unified Communications Manager Information Disclosure Vulnerability
vendor_cisco·2016-08-17·CVSS 5.0
CVE-2016-6364 [MEDIUM] CWE-200 Cisco Unified Communications Manager Information Disclosure Vulnerability
Cisco Unified Communications Manager Information Disclosure Vulnerability
A vulnerability in the User Data Services (UDS) Application Programming Interface (API) for Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view confidential information that should require authentication.
The vulnerability is due to improper authentication controls for certain information returned by the UDS API. An attacker could exploit this vulnerability by accessing the UDS API. An exploit could allow the attacker to view certain information that is confidential and should require authentication to retrieve via the UDS API.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory
Cisco
Cisco Unified Communications Manager Information Disclosure Vulnerability
vendor_cisco
CVE-2016-6364 Cisco Unified Communications Manager Information Disclosure Vulnerability
CVE-2016-6364: Cisco Unified Communications Manager Information Disclosure Vulnerability
A vulnerability in the User Data Services (UDS) Application Programming Interface (API) for Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view confidential information that should require authentication. The vulnerability is due to improper authentication controls for certain information returned by the UDS API. An attacker could exploit this vulnerability by accessing the UDS API. An exploit could allow the attacker to view certain information that is confidential and should require authentication to retrieve via the UDS API. Cisco has released software updates that address this vulnerability.
CWE: CWE-200, CWE-200
Bug IDs: CSCux67855
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-ucmhttp://www.securityfocus.com/bid/92517http://www.securitytracker.com/id/1036650http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-ucmhttp://www.securityfocus.com/bid/92517http://www.securitytracker.com/id/1036650
2016-08-23
Published