CVE-2024-20457
published 2024-11-06CVE-2024-20457: A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.43%
35.6th percentile
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.
This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to access sensitive information from the device.
Affected
93 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
| cisco | cisco_unified_communications_manager_im_and_presence_service | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3c6f-r64x-4f7r: A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated,
ghsa_unreviewed·2024-11-06
CVE-2024-20457 [MEDIUM] CWE-200 GHSA-3c6f-r64x-4f7r: A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated,
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.
This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to access sensitive information from the device.
Cisco
Cisco Unified Communications Manager IM & Presence Service Information Disclosure Vulnerability
vendor_cisco·2024-11-06·CVSS 6.5
CVE-2024-20457 [MEDIUM] CWE-200 Cisco Unified Communications Manager IM & Presence Service Information Disclosure Vulnerability
Cisco Unified Communications Manager IM & Presence Service Information Disclosure Vulnerability
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.
This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to access sensitive information from the device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Th
Cisco
Cisco Unified Communications Manager IM & Presence Service Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20457 Cisco Unified Communications Manager IM & Presence Service Information Disclosure Vulnerability
CVE-2024-20457: Cisco Unified Communications Manager IM & Presence Service Information Disclosure Vulnerability
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to access sensitive information from the device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-200, CWE-200
Bu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-06
Published