First published: Tue Feb 09 2016(Updated: )
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris and Zettabyte File System (ZFS) | =snv_124 | |
Samsung X14J eu | =t-ms14jakucb-1102.5 | |
Zyxel GS1900-10HP firmware | <2.50\(aazi.0\)c0 | |
zzinc KeyMouse | =3.08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1319 is rated as high severity due to the exposure of sensitive encryption keys.
To fix CVE-2016-1319, upgrade to the latest fixed version of Cisco Unified Communications Manager as recommended by Cisco.
CVE-2016-1319 affects Cisco Unified Communications Manager versions 9.1(2) to 11.0(1) and related services.
The potential impacts of CVE-2016-1319 include unauthorized access to sensitive data due to the exposure of encryption keys.
There are no specific workarounds for CVE-2016-1319; updating the affected systems is the recommended solution.