CVE Database
/

CVE-2013-7030

Back to search

CVE-2013-7030

Published: Dec 12, 2013

Modified: Oct 29, 2024

PUBLISHED

Description

The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue

VendorProductVersions

n/a

n/a

affected
n/a

References

30237
exploit
x_refsource_EXPLOIT-DB
cisco-ucm-tftp-info-disc(89649)
vdb-entry
x_refsource_XF
100916
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now