Vulnerability Description
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Emergency Responder | 2.0 |
| Cisco | Mobility Manager | 2.0 |
| Cisco | Unified Communications Manager | 5.0 |
| Cisco | Unified Presence | 1.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/29670
- http://securitytracker.com/id?1019768
- http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.sPatch
- http://www.securityfocus.com/bid/28591
- http://www.vupen.com/english/advisories/2008/1093
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41632
- http://secunia.com/advisories/29670
- http://securitytracker.com/id?1019768
- http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.sPatch
- http://www.securityfocus.com/bid/28591
- http://www.vupen.com/english/advisories/2008/1093
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41632
FAQ
What is CVE-2008-1154?
CVE-2008-1154 is a vulnerability with a CVSS score of 10.0 (HIGH). The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Respo...
How severe is CVE-2008-1154?
CVE-2008-1154 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1154?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Emergency Responder, Cisco Mobility Manager, Cisco Unified Communications Manager, Cisco Unified Presence.