CVE-2009-0632: Critical severity Cisco Unified Communications Manager vulnerability
The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Communications Manager (CUCM)to a version that resolves this vulnerability.Fixed in 4.2(3)SR4b - Upgrade
Upgrade
Cisco Unified Communications Manager (CUCM)to a version that resolves this vulnerability.Fixed in 4.3(2)SR1b - Upgrade
Upgrade
Cisco Unified Communications Manager (CUCM)to a version that resolves this vulnerability.Fixed in 5.1(3e) - Upgrade
Upgrade
Cisco Unified Communications Manager (CUCM)to a version that resolves this vulnerability.Fixed in 6.1(3) - Upgrade
Upgrade
Cisco Unified Communications Manager (CUCM)to a version that resolves this vulnerability.Fixed in 7.0(2)
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0632?
CVE-2009-0632 is rated as a medium severity vulnerability due to its potential to expose sensitive credentials.
How do I fix CVE-2009-0632?
To fix CVE-2009-0632, upgrade to a patched version of Cisco Unified Communications Manager as specified in the security advisory.
What kind of vulnerabilities does CVE-2009-0632 expose?
CVE-2009-0632 exposes privileged directory-service account credentials, which can lead to unauthorized access.
What versions are affected by CVE-2009-0632?
CVE-2009-0632 affects multiple versions of Cisco Unified Communications Manager, specifically versions prior to 4.2(3)SR4b, 4.3(2)SR1b, 5.1(3e), and others listed in the advisory.
What components of Cisco Unified Communications Manager are impacted by CVE-2009-0632?
The CVE-2009-0632 vulnerability affects the IP Phone Personal Address Book (PAB) Synchronizer feature of Cisco Unified Communications Manager.