CVE-2021-1226
published 2021-01-13CVE-2021-1226: A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.91%
56.0th percentile
A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_emergency_responder | — | — |
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | >= 12.5\(1\) < 12.5\(1\)su3 | 12.5\(1\)su3 |
| cisco | prime_license_manager | — | — |
| cisco | prime_license_manager | >= 11.5\(1\) < 11.5\(1\)su9 | 11.5\(1\)su9 |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | >= 11.5\(1\) < 11.5\(1\)su9 | 11.5\(1\)su9 |
| cisco | unified_communications_manager_im_presence_service | — | — |
| cisco | unified_communications_manager_im_presence_service | — | — |
| cisco | unified_communications_manager_im_presence_service | >= 11.5\(1\) < 11.5\(1\)su9 | 11.5\(1\)su9 |
| cisco | unified_communications_manager_im_presence_service | >= 12.5\(1\) < 12.5\(1\)su3 | 12.5\(1\)su3 |
| cisco | unified_communications_products | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | >= 11.5\(1\) < 11.5\(1\)su9 | 11.5\(1\)su9 |
| cisco | unity_connection | >= 12.0\(1\) < 12.0\(1\)su4 | 12.0\(1\)su4 |
| cisco | unity_connection | >= 12.5\(1\) < 12.5\(1\)su3 | 12.5\(1\)su3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Products Information Disclosure Vulnerability
vendor_cisco·2021-01-13·CVSS 4.3
CVE-2021-1226 [MEDIUM] CWE-532 Cisco Unified Communications Products Information Disclosure Vulnerability
Cisco Unified Communications Products Information Disclosure Vulnerability
A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.
The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to
Cisco
Cisco Unified Communications Products Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1226 Cisco Unified Communications Products Information Disclosure Vulnerability
CVE-2021-1226: Cisco Unified Communications Products Information Disclosure Vulnerability
A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those cr
GHSA
GHSA-mg6r-7gcg-995g: A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Editio
ghsa_unreviewed·2022-05-24
CVE-2021-1226 [MEDIUM] CWE-532 GHSA-mg6r-7gcg-995g: A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Editio
A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-13
Published