← Back

CVE-2022-20752

nvd nist
Published: Jul 6, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exploit this vulnerability by observing the time it takes the system to respond to various queries. A successful exploit could allow the attacker to determine a sensitive system password.

Affected (6)

2 products
Unified Communications Manager
Unity Connection
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
From 12.5\(1\) to 12.5\(1\)su6
From 14.0 to 14su1
From 12.5\(1\) to 12.5\(1\)su6
From 14.0 to 14su1
Cisco
From 12.5\(1\) to 12.5\(1\)su6
From 14.0 to 14su1

Timeline

No history available yet.