| Vulnerability Name: | CVE-2018-0474 (CCN-155318) | ||||||||||||
| Assigned: | 2017-11-27 | ||||||||||||
| Published: | 2019-01-09 | ||||||||||||
| Updated: | 2020-08-28 | ||||||||||||
| Summary: | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in configuration pages. An attacker could exploit this vulnerability by logging in to the Cisco Unified Communications Manager web-based management interface and viewing the source code for the configuration page. A successful exploit could allow the attacker to recover passwords and expose those accounts to further attack. | ||||||||||||
| CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-522 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-0474 Source: BID Type: Third Party Advisory, VDB Entry 106538 Source: XF Type: UNKNOWN cisco-cve20180474-info-disc(155318) Source: CCN Type: Cisco Security Advisory cisco-sa-20190109-cucm-creds-disclosr Cisco Unified Communications Manager Digest Credentials Disclosure Vulnerability Source: CISCO Type: Vendor Advisory 20190109 Cisco Unified Communications Manager Digest Credentials Disclosure Vulnerability | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||