NewsSecurity Vulnerabilities

Cisco Unified Communications Products Information Disclosure Vulnerability [CVE-2021-1226]

CVE number – CVE-2021-1226

A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.

The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Vulnerable Products

At the time of publication, this vulnerability affected the following Cisco products:

  • Unified Communications Manager (Unified CM)
  • Unified Communications Manager Session Management Edition (Unified CM SME)
  • Unified Communications Manager IM & Presence Service (Unified CM IM&P)
  • Unity Connection
  • Emergency Responder
  • Prime License Manager

Fixed Software

At the time of publication, the release information in the following table(s) was accurate. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.

The left column lists Cisco software releases, and the right column indicates whether a release was affected by the vulnerability described in this advisory and which release included the fix for this vulnerability.

Unified CM and Unified CM SME: CSCvu52881

Cisco Unified CM and Cisco Unified CM SME ReleasesFirst Fixed Release for This Vulnerability
10.5(2)None planned
11.5(1)11.5(1)SU9
12.0(1)12.0(1)SU4
12.5(1)12.5(1)SU3

Unified CM IM&P: CSCvv32686

Cisco Unified CM IM&P ReleasesFirst Fixed Release for This Vulnerability
10.5(2)None planned
11.5(1)11.5(1)SU9
12.0(1)None planned
12.5(1)12.5(1)SU3

Unity Connection: CSCvv32655

Cisco Unity Connection ReleasesFirst Fixed Release for This Vulnerability
10.5(2)None planned
11.5(1)11.5(1)SU9
12.0(1)12.0(1)SU4
12.5(1)12.5(1)SU3

Emergency Responder: CSCvv32714

Cisco Emergency Responder ReleasesFirst Fixed Release for This Vulnerability
10.5(2)None planned
11.5(1)None planned
12.0(1)None planned
12.5(1)12.5(1)SU3

Prime License Manager: CSCvv68015

Cisco Prime License Manager ReleasesFirst Fixed Release for This Vulnerability
10.5(2)None planned
11.5(1)11.5(1)SU9

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-logging-6QSWKRYz

Duncan

Duncan is a technology professional with over 20 years experience of working in various IT roles. He has a interest in cyber security, and has a wide range of other skills in radio, electronics and telecommunications.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.