First published: Fri Apr 04 2008(Updated: )
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Mobility Manager | =2.0 | |
Cisco Unified Communications Manager | =5.0 | |
Cisco Unified Presence | =1.0 | |
Cisco Unified Presence | =6.0 | |
Cisco Unified Communications Manager | =6.1 | |
Cisco Emergency Responder | =2.0 | |
Cisco Unified Communications Manager | =6.0 | |
Cisco Unified Communications Manager | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.