CVE-2018-0266 describes a medium-severity vulnerability in the web framework of Cisco Unified Communications Manager (CUCM) that allows an authenticated, remote attacker to view sensitive configuration data. The vulnerability, stemming from insufficient protection of database tables, can be exploited by browsing to a specific URL. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential impact is a breach of confidentiality of CUCM configuration parameters.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5\(2.10000.5\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:10.5\(2.10000.5\):*:*:*:*:*:*:* | ||
11.0\(1.10000.10\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:11.0\(1.10000.10\):*:*:*:*:*:*:* | ||
11.5\(1.10000.6\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.10000.6\):*:*:*:*:*:*:* | ||
12.0\(1.10000.10\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.0\(1.10000.10\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.