|
« Back
Severity
Low
Title
DRF Get Schedule Command Injection
Description
The Cisco Unified Communications Manager provides the Disaster Recovery Framework (DRF) in order to allow the exchange of configuration and information between intra-cluster nodes. This allows for a more robust and redundant infrastructure.
Due to a lack of authentication, unauthenticated users can inject commands, including the Get Schedule command which an attacker could use to view when backups are to be performed in order to plan an attack. Details
Category
Information Gathering
Vendor
Cisco
Product
Unified Communications Manager 5.x
Released
2008-04-01
updated
2008-04-01
Response
Patch available
Recommendations
Cisco has released a patch and workarounds to address the issue as discussed in Cisco Advisory cisco-sa-20080403-drf available at:
http://www.cisco.com/warp/public/707/cisco-sa-20080403-drf.shtml
Cisco has also released an applied mitigation bulletin to help customers address the issue:
http://www.cisco.com/warp/public/707/cisco-amb-20080403-drf.shtml
In addition, a VoIP aware IPS product, such as VoIPguard, with signatures to detect attempts to exploit this issue, can be implemented to prevent it from being exploited.
Tracking Id
VSRCS-2008-002
|
Each line represents an individual vulnerability or group of vulnerabilities. For example, "UCM Multiple Hardcoded Passwords" is presented here in a single line but was reported to Nortel as sixteen (16) individual vulnerabilities.
Severity Legend
Click on a level for description
Low
Medium
High
Critical
Vendor Response Legend |