«
Expand/Collapse
52 items tagged "cisco unified"
Related tags:
security [+],
multiple [+],
meetingplace [+],
vulnerabilities [+],
secunia [+],
injection [+],
exploitation [+],
cisco [+],
Software [+],
sql injection [+],
presence [+],
txt [+],
sql [+],
security advisory [+],
safer use [+],
ip phones [+],
denial of service [+],
denial [+],
zero [+],
vsr [+],
videoconferencing system [+],
uccx [+],
train customers [+],
sql statements [+],
session initiation protocol [+],
session id cookie [+],
service [+],
series [+],
response [+],
protocol sip [+],
phone [+],
patch [+],
memory exhaustion [+],
manager component [+],
interactive voice response [+],
free software updates [+],
dos vulnerability [+],
directory traversal vulnerability [+],
database [+],
credential service [+],
command [+],
cisco unified communications manager [+],
cisco sql [+],
cisco callmanager [+],
bugtraq [+],
apache webserver [+],
web conference [+],
web [+],
videoconferencing products [+],
sql commands [+],
security incident response [+],
manager express [+],
incident response team [+],
device [+],
cucme [+],
conference [+],
cisco uvc [+],
cisco product [+],
cisco ios device [+],
cisco ios [+],
cisco security [+],
advisory [+],
xcp [+],
unified communications [+],
setup [+],
service vulnerability [+],
server security [+],
server [+],
security weakness [+],
security restrictions [+],
security response [+],
retired [+],
query interface [+],
query [+],
phones [+],
phone models [+],
password [+],
open query [+],
open [+],
obfuscation [+],
manager agent [+],
malicious users [+],
jabber [+],
ftp [+],
cve [+],
cross site scripting [+],
code execution [+],
code [+],
cisco icm [+],
callmanager [+],
bypass [+],
backend database [+],
arbitrary code [+],
cisco security advisory [+],
vulnerability [+],
videoconferencing [+]
-
-
0:37
»
Packet Storm Security Advisories
Secunia Security Advisory - Multiple vulnerabilities have been reported in Cisco Unified MeetingPlace, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
-
0:37
»
Packet Storm Security Advisories
Secunia Security Advisory - A weakness and two vulnerabilities have been reported in Cisco Unified MeetingPlace, which can be exploited by malicious people to enumerate folders on an affected system and conduct cross-site scripting attacks.
-
-
10:58
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) contain a directory traversal vulnerability that may allow a remote, unauthenticated attacker to retrieve arbitrary files from the filesystem. Cisco has released free software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
-
10:58
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) contain a directory traversal vulnerability that may allow a remote, unauthenticated attacker to retrieve arbitrary files from the filesystem. Cisco has released free software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
-
10:58
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) contain a directory traversal vulnerability that may allow a remote, unauthenticated attacker to retrieve arbitrary files from the filesystem. Cisco has released free software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
-
-
17:44
»
SecuriTeam
Cisco Unified IP Phones 7900 Series devices are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
0:09
»
Packet Storm Security Advisories
Secunia Security Advisory - A vulnerability has been reported in Cisco Unified Presence, which can be exploited by malicious people to cause a DoS (Denial of Service).
-
-
14:52
»
Packet Storm Security Advisories
Cisco Security Advisory - A denial of service (DoS) vulnerability exists in Jabber Extensible Communications Platform (Jabber XCP) and Cisco Unified Presence. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious XML to an affected server. Successful exploitation of this vulnerability could cause elevated memory and CPU utilization, resulting in memory exhaustion and process crashes. Repeated exploitation could result in a sustained DoS condition. There are no workarounds available to mitigate exploitation of this vulnerability.
-
14:52
»
Packet Storm Security Recent Files
Cisco Security Advisory - A denial of service (DoS) vulnerability exists in Jabber Extensible Communications Platform (Jabber XCP) and Cisco Unified Presence. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious XML to an affected server. Successful exploitation of this vulnerability could cause elevated memory and CPU utilization, resulting in memory exhaustion and process crashes. Repeated exploitation could result in a sustained DoS condition. There are no workarounds available to mitigate exploitation of this vulnerability.
-
14:52
»
Packet Storm Security Misc. Files
Cisco Security Advisory - A denial of service (DoS) vulnerability exists in Jabber Extensible Communications Platform (Jabber XCP) and Cisco Unified Presence. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious XML to an affected server. Successful exploitation of this vulnerability could cause elevated memory and CPU utilization, resulting in memory exhaustion and process crashes. Repeated exploitation could result in a sustained DoS condition. There are no workarounds available to mitigate exploitation of this vulnerability.
-
-
19:40
»
Packet Storm Security Advisories
Secunia Security Advisory - A security issue has been reported in Cisco Unified Communications Manager and Cisco Unified Presence Server, which can be exploited by malicious people to disclose sensitive information.
-
17:16
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Unified Communications Manager (previously known as Cisco CallManager) and Cisco Unified Presence Server contain an open query interface that could allow an unauthenticated, remote attacker to disclose the contents of the underlying databases on affected product versions. Cisco has released free updated software for most supported releases. A security patch file is also available for all supported versions that will remediate this issue. The patch may be applied to active systems without requiring a reload. Customers are advised to apply a fixed version or upgrade to a fixed train. Customers who need to stay on a version for which updated software is not currently available or who can not immediately apply the update are advised to apply the patch. No workarounds are available for this issue.
-
17:16
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Unified Communications Manager (previously known as Cisco CallManager) and Cisco Unified Presence Server contain an open query interface that could allow an unauthenticated, remote attacker to disclose the contents of the underlying databases on affected product versions. Cisco has released free updated software for most supported releases. A security patch file is also available for all supported versions that will remediate this issue. The patch may be applied to active systems without requiring a reload. Customers are advised to apply a fixed version or upgrade to a fixed train. Customers who need to stay on a version for which updated software is not currently available or who can not immediately apply the update are advised to apply the patch. No workarounds are available for this issue.
-
17:16
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco Unified Communications Manager (previously known as Cisco CallManager) and Cisco Unified Presence Server contain an open query interface that could allow an unauthenticated, remote attacker to disclose the contents of the underlying databases on affected product versions. Cisco has released free updated software for most supported releases. A security patch file is also available for all supported versions that will remediate this issue. The patch may be applied to active systems without requiring a reload. Customers are advised to apply a fixed version or upgrade to a fixed train. Customers who need to stay on a version for which updated software is not currently available or who can not immediately apply the update are advised to apply the patch. No workarounds are available for this issue.
-
-
19:14
»
SecuriTeam
This vulnerability allows remote attackers to inject arbitrary SQL into the backend database on vulnerable installations of Cisco Unified CM.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
22:38
»
Packet Storm Security Advisories
Secunia Security Advisory - Some security issues have been reported in Cisco Unified IP Phone models, which can be exploited by malicious, local users to bypass certain security restrictions and perform certain actions with escalated privileges.
-
11:49
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Unified IP Phones 7900 Series devices, also known as TNP phones, are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software. These three vulnerabilities are classified as two privilege escalation vulnerabilities and one signature bypass vulnerability. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
11:49
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Unified IP Phones 7900 Series devices, also known as TNP phones, are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software. These three vulnerabilities are classified as two privilege escalation vulnerabilities and one signature bypass vulnerability. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
11:49
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco Unified IP Phones 7900 Series devices, also known as TNP phones, are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software. These three vulnerabilities are classified as two privilege escalation vulnerabilities and one signature bypass vulnerability. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
-
19:34
»
Packet Storm Security Advisories
Zero Day Initiative Advisory 11-143 - This vulnerability allows remote attackers to inject arbitrary SQL into the backend database on vulnerable installations of Cisco Unified CM. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Call Manager component. The system exposes an Apache webserver which contains a JSP script vulnerable to SQL injection. The xmldirectorylist.jsp file does not properly validate the f, l, and n parameters before passing them to the database. A remote attacker can abuse this to inject SQL statements to be evaluated by the underlying database.
-
19:34
»
Packet Storm Security Recent Files
Zero Day Initiative Advisory 11-143 - This vulnerability allows remote attackers to inject arbitrary SQL into the backend database on vulnerable installations of Cisco Unified CM. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Call Manager component. The system exposes an Apache webserver which contains a JSP script vulnerable to SQL injection. The xmldirectorylist.jsp file does not properly validate the f, l, and n parameters before passing them to the database. A remote attacker can abuse this to inject SQL statements to be evaluated by the underlying database.
-
19:34
»
Packet Storm Security Misc. Files
Zero Day Initiative Advisory 11-143 - This vulnerability allows remote attackers to inject arbitrary SQL into the backend database on vulnerable installations of Cisco Unified CM. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Call Manager component. The system exposes an Apache webserver which contains a JSP script vulnerable to SQL injection. The xmldirectorylist.jsp file does not properly validate the f, l, and n parameters before passing them to the database. A remote attacker can abuse this to inject SQL statements to be evaluated by the underlying database.
-
-
13:58
»
SecuriTeam
Multiple Vulnerabilities were identified in Cisco Unified Videoconferencing Products.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
17:54
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco Unified ICM.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
20:41
»
Packet Storm Security Advisories
Secunia Security Advisory - Multiple weaknesses and vulnerabilities have been reported in Cisco Unified Videoconferencing, which can be exploited by malicious, local users to disclose sensitive information and gain escalated privileges, by malicious users to compromise a vulnerable system, and by malicious people to hijack another user's session, disclose sensitive information, and potentially compromise a vulnerable system.
-
16:35
»
Packet Storm Security Advisories
Cisco Unified Videoconferencing system versions 3515,3522,3527,5230,3545,5110 and 5115 suffer from hard-coded credential, service misconfiguration, weak session ID, cookie storing of credentials, command injection and weak obfuscation vulnerabilities.
-
16:35
»
Packet Storm Security Recent Files
Cisco Unified Videoconferencing system versions 3515,3522,3527,5230,3545,5110 and 5115 suffer from hard-coded credential, service misconfiguration, weak session ID, cookie storing of credentials, command injection and weak obfuscation vulnerabilities.
-
16:35
»
Packet Storm Security Misc. Files
Cisco Unified Videoconferencing system versions 3515,3522,3527,5230,3545,5110 and 5115 suffer from hard-coded credential, service misconfiguration, weak session ID, cookie storing of credentials, command injection and weak obfuscation vulnerabilities.
-
15:46
»
Packet Storm Security Advisories
This is the Cisco Product Security Incident Response Team (PSIRT) response to a posting entitled "Cisco Unified Videoconferencing multiple vulnerabilities" by Florent Daigniere of Matta Consulting regarding vulnerabilities in the Cisco Unified Videoconferencing (Cisco UVC) 5100 series products. Several of the vulnerabilities also impact Cisco Unified Videoconferencing 5200 and 3500 Series Products.
-
15:46
»
Packet Storm Security Misc. Files
This is the Cisco Product Security Incident Response Team (PSIRT) response to a posting entitled "Cisco Unified Videoconferencing multiple vulnerabilities" by Florent Daigniere of Matta Consulting regarding vulnerabilities in the Cisco Unified Videoconferencing (Cisco UVC) 5100 series products. Several of the vulnerabilities also impact Cisco Unified Videoconferencing 5200 and 3500 Series Products.
-
-
18:42
»
SecuriTeam
Cisco Unified Presence contains two denial of service vulnerabilities that affect the processing of Session Initiation Protocol (SIP) messages.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
23:38
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Unified Presence contains two denial of service (DoS) vulnerabilities that affect the processing of Session Initiation Protocol (SIP) messages. Exploitation of these vulnerabilities could cause an interruption of presence services. suffers from a denial of service vulnerability.
-
23:38
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Unified Presence contains two denial of service (DoS) vulnerabilities that affect the processing of Session Initiation Protocol (SIP) messages. Exploitation of these vulnerabilities could cause an interruption of presence services. suffers from a denial of service vulnerability.
-
-
11:51
»
Packet Storm Security Recent Files
Cisco Security Advisory - Devices running Cisco IOS Software and configured for Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) operation are affected by two denial of service vulnerabilities that may result in a device reload if successfully exploited. The vulnerabilities are triggered when the Cisco IOS device processes specific, malformed Skinny Call Control Protocol (SCCP) messages.
-
11:51
»
Packet Storm Security Advisories
Cisco Security Advisory - Devices running Cisco IOS Software and configured for Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) operation are affected by two denial of service vulnerabilities that may result in a device reload if successfully exploited. The vulnerabilities are triggered when the Cisco IOS device processes specific, malformed Skinny Call Control Protocol (SCCP) messages.
-
-
12:00
»
Packet Storm Security Recent Files
Cisco Security Advisory - Multiple vulnerabilities exist in Cisco Unified MeetingPlace. These range from insufficient validation of SQL commands to privilege escalation.
-
12:00
»
Packet Storm Security Advisories
Cisco Security Advisory - Multiple vulnerabilities exist in Cisco Unified MeetingPlace. These range from insufficient validation of SQL commands to privilege escalation.