René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

103 lines
3.3 KiB
JSON

{
"id": "CVE-2008-2730",
"sourceIdentifier": "ykramarz@cisco.com",
"published": "2008-06-26T17:41:00.000",
"lastModified": "2017-08-08T01:31:16.870",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsj90843."
},
{
"lang": "es",
"value": "El Servicio Real -Time Information Server (RIS) Data Collector de Cisco Unified Communications Manager (CUCM) 5.x versiones anteriores a la 5.1(3) y 6.x versiones anteriores a la 6.1(1) permite a atacantes remotos evitar la autenticaci\u00f3n y obtener informaci\u00f3n sobre la configuraci\u00f3n en cluster y estad\u00edsticas, a trav\u00e9s de una conexi\u00f3n directa TCP al puerto de servicio, tambi\u00e9n conocida como Bug ID CSCsj90843."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:unified_communications_manager:5.1:*:*:*:*:*:*:*",
"matchCriteriaId": "640BFEE2-B364-411E-B641-7471B88ED7CC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:unified_communications_manager:6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "6BC6EF34-D23D-45CA-A907-A47993CC061E"
}
]
}
]
}
],
"references": [
{
"url": "http://www.cisco.com/en/US/products/products_security_advisory09186a00809b9011.shtml",
"source": "ykramarz@cisco.com",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/bid/29935",
"source": "ykramarz@cisco.com"
},
{
"url": "http://www.securitytracker.com/id?1020361",
"source": "ykramarz@cisco.com"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1933/references",
"source": "ykramarz@cisco.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43355",
"source": "ykramarz@cisco.com"
}
]
}