First published: Thu Jul 18 2013(Updated: )
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted credentials by leveraging metadata, aka Bug ID CSCuh01051.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =7.1\(2a\) | |
Cisco Unified Communications Manager | =7.1\(2a\)su1 | |
Cisco Unified Communications Manager | =7.1\(2b\) | |
Cisco Unified Communications Manager | =7.1\(2b\)su1 | |
Cisco Unified Communications Manager | =7.1\(3\) | |
Cisco Unified Communications Manager | =7.1\(3a\) | |
Cisco Unified Communications Manager | =7.1\(3a\)su1 | |
Cisco Unified Communications Manager | =7.1\(3a\)su1a | |
Cisco Unified Communications Manager | =7.1\(3b\) | |
Cisco Unified Communications Manager | =7.1\(3b\)su1 | |
Cisco Unified Communications Manager | =7.1\(3b\)su2 | |
Cisco Unified Communications Manager | =7.1\(5\) | |
Cisco Unified Communications Manager | =7.1\(5\)su1 | |
Cisco Unified Communications Manager | =7.1\(5\)su1a | |
Cisco Unified Communications Manager | =7.1\(5a\) | |
Cisco Unified Communications Manager | =7.1\(5b\) | |
Cisco Unified Communications Manager | =7.1\(5b\)su1 | |
Cisco Unified Communications Manager | =7.1\(5b\)su1a | |
Cisco Unified Communications Manager | =7.1\(5b\)su2 | |
Cisco Unified Communications Manager | =7.1\(5b\)su3 | |
Cisco Unified Communications Manager | =7.1\(5b\)su4 | |
Cisco Unified Communications Manager | =7.1\(5b\)su5 | |
Cisco Unified Communications Manager | =7.1\(5b\)su6 | |
Cisco Unified Communications Manager | =8.0 | |
Cisco Unified Communications Manager | =8.0\(1\) | |
Cisco Unified Communications Manager | =8.0\(2\) | |
Cisco Unified Communications Manager | =8.0\(2a\) | |
Cisco Unified Communications Manager | =8.0\(2b\) | |
Cisco Unified Communications Manager | =8.0\(2c\) | |
Cisco Unified Communications Manager | =8.0\(2c\)su1 | |
Cisco Unified Communications Manager | =8.0\(3\) | |
Cisco Unified Communications Manager | =8.0\(3a\) | |
Cisco Unified Communications Manager | =8.0\(3a\)su1 | |
Cisco Unified Communications Manager | =8.0\(3a\)su2 | |
Cisco Unified Communications Manager | =8.0\(3a\)su3 | |
Cisco Unified Communications Manager | =8.5 | |
Cisco Unified Communications Manager | =8.5\(1\) | |
Cisco Unified Communications Manager | =8.5\(1\)su1 | |
Cisco Unified Communications Manager | =8.5\(1\)su2 | |
Cisco Unified Communications Manager | =8.5\(1\)su3 | |
Cisco Unified Communications Manager | =8.5\(1\)su4 | |
Cisco Unified Communications Manager | =8.5\(1\)su5 | |
Cisco Unified Communications Manager | =8.6 | |
Cisco Unified Communications Manager | =8.6\(1\) | |
Cisco Unified Communications Manager | =8.6\(1a\) | |
Cisco Unified Communications Manager | =8.6\(2\) | |
Cisco Unified Communications Manager | =8.6\(2a\) | |
Cisco Unified Communications Manager | =8.6\(2a\)su1 | |
Cisco Unified Communications Manager | =8.6\(2a\)su2 | |
Cisco Unified Communications Manager | =8.6\(2a\)su3 | |
Cisco Unified Communications Manager | =8.6\(3\) | |
Cisco Unified Communications Manager | =8.6\(4\) | |
Cisco Unified Communications Manager | =9.0\(1\) | |
Cisco Unified Communications Manager | =9.1\(1\) | |
Cisco Unified Communications Manager | =9.1\(1a\) | |
Cisco Unified Communications Manager | =9.1.1\(a\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3404 has a high severity rating due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2013-3404, it is recommended to upgrade to a patched version of Cisco Unified Communications Manager as specified in the vendor's advisory.
CVE-2013-3404 affects Cisco Unified Communications Manager versions 7.1(x) through 9.1(1a), excluding version 9.1(1a) itself.
CVE-2013-3404 can be exploited through SQL injection attacks, which can lead to unauthorized access to encrypted credentials.
Yes, CVE-2013-3404 remains a concern for users who have not upgraded their affected Cisco Unified Communications Manager versions.