Title : Cisco UC Disaster Recovery Framework Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-1093 CVE ID : CVE-2008-1154
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-03
Technical Description
A vulnerability has been identified in various Cisco products, which could be exploited by remote attackers to cause a denial of service, disclose sensitive information, or take complete control of an affected system. This issue is caused by a design error in the Disaster Recovery Framework (DRF) Master server that does not perform authentication on requests received over the network, which could be exploited by remote unauthenticated attackers to perform DRF-related tasks and create a denial of service condition, obtain sensitive configuration information, overwrite configuration parameters, or execute arbitrary commands with full administrative privileges.