CVE-2016-1319: Infoleak
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1319?
CVE-2016-1319 is rated as high severity due to the exposure of sensitive encryption keys.
How do I fix CVE-2016-1319?
To fix CVE-2016-1319, upgrade to the latest fixed version of Cisco Unified Communications Manager as recommended by Cisco.
What systems are affected by CVE-2016-1319?
CVE-2016-1319 affects Cisco Unified Communications Manager versions 9.1(2) to 11.0(1) and related services.
What are the potential impacts of CVE-2016-1319?
The potential impacts of CVE-2016-1319 include unauthorized access to sensitive data due to the exposure of encryption keys.
Is there a workaround for CVE-2016-1319?
There are no specific workarounds for CVE-2016-1319; updating the affected systems is the recommended solution.