>> Cisco Unified Communications Manager and Presence Server Security Bypass Issues
Title : Cisco Unified Communications Manager and Presence Server Security Bypass Issues VUPEN ID : VUPEN/ADV-2007-2511 CVE ID : CVE-2007-3775 - CVE-2007-3776
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-12
Technical Description
Two vulnerabilities have been identified in Cisco Unified Communications Manager (CUCM), formerly CallManager, and Cisco Unified Presence Server (CUPS), which could be exploited by malicious users to bypass security checks. These issues are caused by unspecified errors that could allow an unauthorized administrator to activate and terminate CUCM / CUPS system services and access SNMP configuration information, leading to a denial of service condition and the disclosure of sensitive SNMP details (including community strings).