Title : Cisco Unity Express Expired Password Reset Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2006-1613 CVE ID : CVE-2006-2166
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-05-02
Technical Description
A vulnerability has been identified in Cisco Unity Express (CUE), which could be exploited by malicious users to bypass security restrictions and obtain elevated privileges. This flaw is due to an error in the HTTP management interface that does not properly validate password changes, which could be exploited by an unprivileged user to change the password for another user (e.g. an expired administrator's password) and gain complete administrative control of a vulnerable CUE module.