Vulnerability Description
The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Communications Manager | 4.1 |
Related Weaknesses (CWE)
References
- http://osvdb.org/52589
- http://secunia.com/advisories/34238
- http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a00
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a8643c.sPatchVendor Advisory
- http://www.securityfocus.com/bid/34082
- http://www.securitytracker.com/id?1021839
- http://www.vupen.com/english/advisories/2009/0675PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49196
- http://osvdb.org/52589
- http://secunia.com/advisories/34238
- http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a00
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a8643c.sPatchVendor Advisory
- http://www.securityfocus.com/bid/34082
- http://www.securitytracker.com/id?1021839
- http://www.vupen.com/english/advisories/2009/0675PatchVendor Advisory
FAQ
What is CVE-2009-0632?
CVE-2009-0632 is a vulnerability with a CVSS score of 9.0 (HIGH). The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1...
How severe is CVE-2009-0632?
CVE-2009-0632 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0632?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Communications Manager.