Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any user with an expired password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cisco Unity Express 用户认证 本地权限提升漏洞
Vulnerability Description
Cisco Unity是面向企业级机构的高级统一通信解决方案可以提供强大的消息发送服务和智能化的语音消息发送服务。 Cisco Unity在对用户认证的处理上存在漏洞,本地攻击者可能利用此漏洞提升自己的权限。 Cisco Unity处理基于HTTP的管理界面的认证过程中存在问题,一个已通过认证的普通用户可以通过HTTP界面修改一个用户的口令只要此用户的口令被标记为已过期,如果目标用户来管理员,则攻击者可以获取设备的管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A