First published: Mon Aug 29 2011(Updated: )
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Presence Server 6.x, 7.x, 8.0, and 8.5 before 8.5xnr allow remote attackers to read database data by connecting to a query interface through an SSL session, aka Bug IDs CSCti81574, CSCto63060, CSCto72183, and CSCto73833.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =8.5\(1\) | |
Cisco Unified Communications Manager | =6.1\(3a\) | |
Cisco Unified Communications Manager | =6.1\(2\) | |
Cisco Unified Communications Manager | =6.1\(3b\)su1 | |
Cisco Unified Communications Manager | =7.1\(2b\)su1 | |
Cisco Unified Communications Manager | =7.1\(2b\) | |
Cisco Unified Communications Manager | =6.1\(2\)su1a | |
Cisco Unified Communications Manager | =7.1\(3b\) | |
Cisco Unified Communications Manager | =6.1\(4\)su1 | |
Cisco Unified Communications Manager | =6.1\(4\) | |
Cisco Unified Communications Manager | =7.1\(2a\)su1 | |
Cisco Unified Communications Manager | =7.1\(3b\)su1 | |
Cisco Unified Communications Manager | =7.1\(3a\)su1a | |
Cisco Unified Communications Manager | =7.1\(5b\)su1 | |
Cisco Unified Communications Manager | =6.1\(5\)su1 | |
Cisco Unified Communications Manager | =6.1\(4a\) | |
Cisco Unified Communications Manager | =7.1\(5b\)su3 | |
Cisco Unified Communications Manager | =6.1\(5\)su2 | |
Cisco Unified Communications Manager | =6.1\(3\) | |
Cisco Unified Communications Manager | =7.1\(3\) | |
Cisco Unified Communications Manager | =6.1\(4a\)su2 | |
Cisco Unified Communications Manager | =7.1\(2a\) | |
Cisco Unified Communications Manager | =6.1\(1\) | |
Cisco Unified Communications Manager | =7.1\(5b\) | |
Cisco Unified Communications Manager | =7.0\(2a\) | |
Cisco Unified Communications Manager | =8.0 | |
Cisco Unified Communications Manager | =7.0\(1\)su1 | |
Cisco Unified Communications Manager | =7.0\(1\)su1a | |
Cisco Unified Communications Manager | =7.1\(5b\)su2 | |
Cisco Unified Communications Manager | =7.1\(5\) | |
Cisco Unified Communications Manager | =7.1\(5a\) | |
Cisco Unified Communications Manager | =6.1\(1b\) | |
Cisco Unified Communications Manager | =6.1\(3b\) | |
Cisco Unified Communications Manager | =7.0\(2a\)su2 | |
Cisco Unified Communications Manager | =6.1\(5\) | |
Cisco Unified Communications Manager | =7.1\(5b\)su1a | |
Cisco Unified Communications Manager | =7.1\(5\)su1a | |
Cisco Unified Communications Manager | =8.5 | |
Cisco Unified Communications Manager | =7.1\(5\)su1 | |
Cisco Unified Communications Manager | =7.1\(3a\) | |
Cisco Unified Communications Manager | =6.1\(2\)su1 | |
Cisco Unified Communications Manager | =7.0\(2a\)su1 | |
Cisco Unified Communications Manager | =7.1\(3a\)su1 | |
Cisco Unified Communications Manager | =6.0 | |
Cisco Unified Communications Manager | =6.1\(1a\) | |
Cisco Unified Communications Manager | =8.5\(1\)su1 | |
Cisco Unified Communications Manager | =7.0\(2\) | |
Cisco Unified Communications Manager | =7.1\(3b\)su2 | |
Cisco Unified Presence Server | =8.5 | |
Cisco Unified Presence Server | =7.0\(2\) | |
Cisco Unified Presence Server | =7.0\(4\) | |
Cisco Unified Presence Server | =7.0\(6\) | |
Cisco Unified Presence Server | =7.0\(9\) | |
Cisco Unified Presence Server | =6.0\(1\) | |
Cisco Unified Presence Server | =6.0\(3\) | |
Cisco Unified Presence Server | =8.5\(3\) | |
Cisco Unified Presence Server | =7.0\(8\) | |
Cisco Unified Presence Server | =6.0\(6\) | |
Cisco Unified Presence Server | =8.5\(2\) | |
Cisco Unified Presence Server | =6.0\(2\) | |
Cisco Unified Presence Server | =7.0\(5\) | |
Cisco Unified Presence Server | =7.0\(3\) | |
Cisco Unified Presence Server | =6.0\(7\) | |
Cisco Unified Presence Server | =8.0 | |
Cisco Unified Presence Server | =7.0\(7\) | |
Cisco Unified Presence Server | =6.0\(4\) | |
Cisco Unified Presence Server | =7.0\(1\) | |
Cisco Unified Presence Server | =8.5\(1\) | |
Cisco Unified Presence Server | =6.0\(5\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1643 has a medium severity rating as it allows remote attackers to read database data.
To mitigate CVE-2011-1643, upgrade Cisco Unified Communications Manager or Cisco Unified Presence Server to a version that includes security updates addressing the vulnerability.
CVE-2011-1643 affects Cisco Unified Communications Manager 6.x, 7.x (before 7.1(5b)su4), 8.0, 8.5 (before 8.5(1)su2) and Cisco Unified Presence Server 6.x, 7.x, 8.0, 8.5 (before certain versions).
Yes, CVE-2011-1643 can be exploited remotely, allowing attackers to access sensitive database information.
Yes, organizations using affected Cisco products without the recommended updates are at risk of exploitation and data breaches associated with CVE-2011-1643.