CVE-2013-7030 describes a sensitive information disclosure vulnerability in the TFTP service of Cisco Unified Communications Manager (CUCM). Remote attackers can leverage an RRQ operation to extract cleartext user credentials from configuration files, specifically the UseUserCredential field in SPDefault.cnf.xml. This vulnerability has a high CVSS score of 7.3, indicating a low attack complexity and potential for significant impact on confidentiality, though Cisco disputes its significance, citing expected behavior and a documented mitigation. While not listed in CISA KEV, an ExploitDB entry exists, but there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.