Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Administrator role, aka Bug ID CSCtd45141.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cuc | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-02-29 17:55
Updated : 2012-02-29 21:00
NVD link : CVE-2012-0366
Mitre link : CVE-2012-0366
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cisco
- unity_connection