First published: Wed Oct 08 2008(Updated: )
Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Server | =5.0 | |
Cisco Unity Server | =4.0 | |
Cisco Unity Server | =7.0\(2\) | |
Cisco Unity Server | =4.0\(4\)-sr1 | |
Cisco Unity Server | =5.0\(1\) | |
Cisco Unity Server | =4.0\(3\) | |
Cisco Unity Server | =4.1\(1\) | |
Cisco Unity Server | =4.0\(2\) | |
Cisco Unity Server | =4.0\(5\) | |
Cisco Unity Server | =4.2\(1\) | |
Cisco Unity Server | =4.0\(4\) | |
Cisco Unity Server | =4.0\(3\)-sr1 | |
Cisco Unity Server | =7.0 | |
Cisco Unity Server | =4.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3814 is considered a critical vulnerability due to its potential for authentication bypass and system modification.
To fix CVE-2008-3814, upgrade to Cisco Unity versions 4.2(1)ES161, 5.0(1)ES53, or 7.0(2)ES8 or later.
CVE-2008-3814 affects Cisco Unity versions 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8.
An attacker exploiting CVE-2008-3814 could bypass authentication and read or modify sensitive system configuration parameters.
Yes, CVE-2008-3814 specifically affects systems using anonymous authentication in Cisco Unity.