CVE-2018-0266Sensitive Information Exposure in Cisco Unified Communications Manager

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 45.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 13

Description

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker to view configuration parameters. Cisco Bug IDs: CSCvf20218.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5cisco/cisco_unified_communications_managerCisco Unified Communications Manager

🔴Vulnerability Details

2
GHSA
GHSA-q9h8-j8cr-j8q5: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data2022-05-13
CVEList
CVE-2018-0266: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data2018-04-19

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager HTTP Interface Information Disclosure Vulnerability2018-04-18
CVE-2018-0266 — Sensitive Information Exposure in Cisco | cvebase