CVE-2016-6464
published 2016-12-14CVE-2016-6464: A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
3.12%
86.4th percentile
A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view information on web pages that should be restricted. More Information: CSCva49629. Known Affected Releases: 11.5(1). Known Fixed Releases: 11.5(1.12000.2) 12.0(0.98000.181).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager_im_and_presence_service | — | — |
| cisco | unified_communications_manager_im_and_presence_service | — | — |
| cisco | unified_communications_manager_im_and_presence_service | — | — |
| cisco | unified_communications_manager_im_and_presence_service | — | — |
| cisco | unified_communications_manager_im_and_presence_service | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability
vendor_cisco·2016-12-07·CVSS 5.0
CVE-2016-6464 [MEDIUM] CWE-200 Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability
Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability
A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view information on web pages that should be restricted.
The vulnerability is due to a lack of proper input validation performed on the HTTP packet header. An attacker could exploit this vulnerability by sending a crafted packet to the targeted device. An exploit could allow the attacker to view web pages that should have been restricted.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisc
Cisco
Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability
vendor_cisco
CVE-2016-6464 Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability
CVE-2016-6464: Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability
A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view information on web pages that should be restricted. The vulnerability is due to a lack of proper input validation performed on the HTTP packet header. An attacker could exploit this vulnerability by sending a crafted packet to the targeted device. An exploit could allow the attacker to view web pages that should have been restricted. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCva49629
GHSA
GHSA-rc2h-r2hc-7r57: A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, re
ghsa_unreviewed·2022-05-17
CVE-2016-6464 [HIGH] CWE-200 GHSA-rc2h-r2hc-7r57: A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, re
A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view information on web pages that should be restricted. More Information: CSCva49629. Known Affected Releases: 11.5(1). Known Fixed Releases: 11.5(1.12000.2) 12.0(0.98000.181).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/94802http://www.securitytracker.com/id/1037412https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-ucmhttp://www.securityfocus.com/bid/94802http://www.securitytracker.com/id/1037412https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-ucm
2016-12-14
Published