10
2008
Authentication Bypass in Cisco Unity
A vulnerability exists in Cisco Unity that could allow an unauthenticated user to view or modify some of the configuration parameters of the Cisco Unity server. Cisco has released free software updates that address this vulnerability. A workaround that mitigates this vulnerability is available.
Vulnerable Products
All Cisco Unity versions, 4.x, 5.x and 7.x, may be affected by this vulnerability.
Details
Cisco Unity servers may be affected by an authentication bypass when they are configured for anonymous authentication. Anonymous authentication is used when Cisco Unity servers are authenticated to the subscriber instead of Microsoft Windows (Integrated Windows authentication). By default, Cisco Unity is configured so that the administrator uses the Integrated Windows authentication method for authentication.
Details on authentication mechanisms can be found in the Installation Guide for Cisco Unity in the Authentication Methods Available for the Cisco Unity Administrator section.
This authentication bypass vulnerability allows an unauthenticated user the ability to view or modify some system configuration parameters. No credentials, personally identifiable, or user information can be obtained through exploitation of this vulnerability.
Impact
Successful exploitation of the vulnerability may result in an unauthenticated user viewing or altering some configuration parameters of the Cisco Unity server.
More info on http://www.cisco.com/warp/public/707/cisco-sa-20081008-unity.shtml
Related Posts
Leave a comment
Archives
- February 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008

An article by








