CVE-2022-20752: Cisco Unified Communications Products Timing Attack Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exploit this vulnerability by observing the time it takes the system to respond to various queries. A successful exploit could allow the attacker to determine a sensitive system password.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20752?
CVE-2022-20752 is a vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection.
How does CVE-2022-20752 impact my system?
CVE-2022-20752 allows an unauthenticated, remote attacker to perform a timing attack, potentially leading to unauthorized access or information disclosure.
What software is affected by CVE-2022-20752?
CVE-2022-20752 affects Cisco Unified Communications Manager (Unified CM) versions 12.5(1) and 14.0, as well as Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and Cisco Unity Connection versions 12.5(1) and 14.0.
What is the severity rating of CVE-2022-20752?
CVE-2022-20752 has a severity rating of 5.3 (Medium).
How can I mitigate the vulnerability CVE-2022-20752?
To mitigate CVE-2022-20752, Cisco recommends upgrading to a fixed software release as described in the Cisco Security Advisory.