>> Cisco UCM Denial of Service and Authentication Bypass Vulnerabilities
Title : Cisco UCM Denial of Service and Authentication Bypass Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1933 CVE ID : CVE-2008-2061 - CVE-2008-2062 - CVE-2008-2730 CWE ID : CWE-20 - CWE-287
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-06-26
Technical Description
Multiple vulnerabilities have been identified in Cisco Unified Communications Manager (CUCM), which could be exploited by attackers to bypass security restrictions or cause a denial of service.
The first is caused by an error in the Computer Telephony Integration (CTI) Manager service when handling malformed input sent to port 2748/TCP, which could be exploited to cause the interruption of voice services, creating a denial of service condition.
The second vulnerability is caused by an error in the Real-Time Information Server (RIS) Data Collector service, which could allow attackers to bypass authentication checks and gain read-only access to information about a CUCM cluster including performance statistics, user names, and configured IP phones.