Cisco Unified Communications Products Information Disclosure Vulnerability [CVE-2021-1226]
CVE number – CVE-2021-1226
A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.
The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Vulnerable Products
At the time of publication, this vulnerability affected the following Cisco products:
- Unified Communications Manager (Unified CM)
- Unified Communications Manager Session Management Edition (Unified CM SME)
- Unified Communications Manager IM & Presence Service (Unified CM IM&P)
- Unity Connection
- Emergency Responder
- Prime License Manager
Fixed Software
At the time of publication, the release information in the following table(s) was accurate. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.
The left column lists Cisco software releases, and the right column indicates whether a release was affected by the vulnerability described in this advisory and which release included the fix for this vulnerability.
Unified CM and Unified CM SME: CSCvu52881
Cisco Unified CM and Cisco Unified CM SME Releases | First Fixed Release for This Vulnerability |
---|---|
10.5(2) | None planned |
11.5(1) | 11.5(1)SU9 |
12.0(1) | 12.0(1)SU4 |
12.5(1) | 12.5(1)SU3 |
Unified CM IM&P: CSCvv32686
Cisco Unified CM IM&P Releases | First Fixed Release for This Vulnerability |
---|---|
10.5(2) | None planned |
11.5(1) | 11.5(1)SU9 |
12.0(1) | None planned |
12.5(1) | 12.5(1)SU3 |
Unity Connection: CSCvv32655
Cisco Unity Connection Releases | First Fixed Release for This Vulnerability |
---|---|
10.5(2) | None planned |
11.5(1) | 11.5(1)SU9 |
12.0(1) | 12.0(1)SU4 |
12.5(1) | 12.5(1)SU3 |
Emergency Responder: CSCvv32714
Cisco Emergency Responder Releases | First Fixed Release for This Vulnerability |
---|---|
10.5(2) | None planned |
11.5(1) | None planned |
12.0(1) | None planned |
12.5(1) | 12.5(1)SU3 |
Prime License Manager: CSCvv68015
Cisco Prime License Manager Releases | First Fixed Release for This Vulnerability |
---|---|
10.5(2) | None planned |
11.5(1) | 11.5(1)SU9 |
This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-logging-6QSWKRYz
![Cisco Unified Communications Products Information Disclosure Vulnerability [CVE-2021-1226]](https://i0.wp.com/www.systemtek.co.uk/wp-content/uploads/2022/01/blank-profile-hi.png?resize=100%2C100)
Duncan is a technology professional with over 20 years experience of working in various IT roles. He has a interest in cyber security, and has a wide range of other skills in radio, electronics and telecommunications.