Vulnerability Details CVE-2013-4869
Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server through 9.1(2) use the same CTI and database-encryption key across different customers' installations, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key, aka Bug IDs CSCsc69187 and CSCui01756. NOTE: the vendor has provided a statement that the "hard-coded static encryption key is considered a hardening issue rather than a vulnerability, and as such, has a CVSS score of 0/0."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.8%
Products affected by CVE-2013-4869
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(1)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2a)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2b)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2b)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3a)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3a)su1a
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3b)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3b)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3b)su2
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5)su1a
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5a)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su1a
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su2
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su3
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su4
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su5
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su6
-
cpe:2.3:a:cisco:unified_communications_manager:8.0
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2a)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2b)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2c)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2c)su1
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3a)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3a)su2
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3a)su3
-
cpe:2.3:a:cisco:unified_communications_manager:8.0_base
-
cpe:2.3:a:cisco:unified_communications_manager:8.5
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su1
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su2
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su3
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su4
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su5
-
cpe:2.3:a:cisco:unified_communications_manager:8.5.1
-
cpe:2.3:a:cisco:unified_communications_manager:8.5_base
-
cpe:2.3:a:cisco:unified_communications_manager:8.6
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(1)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(1a)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2a)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2a)su2
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2a)su3
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(3)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(4)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6.1
-
cpe:2.3:a:cisco:unified_communications_manager:8.6.2
-
cpe:2.3:a:cisco:unified_communications_manager:8.6_base
-
cpe:2.3:a:cisco:unified_communications_manager:9.0
-
cpe:2.3:a:cisco:unified_communications_manager:9.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager:9.1
-
cpe:2.3:a:cisco:unified_communications_manager:9.1(1)
-
cpe:2.3:a:cisco:unified_communications_manager:9.1(1a)
-
cpe:2.3:a:cisco:unified_communications_manager:9.1(2)