CVE-2024-20457

A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.

This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to access sensitive information from the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ciscoCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
ciscounified_communications_manager_im_and_presence_service
10.0\(1\)
ciscounified_communications_manager_im_and_presence_service
10.0\(1\)su1
ciscounified_communications_manager_im_and_presence_service
10.0\(1\)su2
ciscounified_communications_manager_im_and_presence_service
10.5\(1\)
ciscounified_communications_manager_im_and_presence_service
10.5\(1\)su1
ciscounified_communications_manager_im_and_presence_service
10.5\(1\)su2
ciscounified_communications_manager_im_and_presence_service
10.5\(1\)su3
ciscounified_communications_manager_im_and_presence_service
10.5\(2\)
ciscounified_communications_manager_im_and_presence_service
10.5\(2\)su1
ciscounified_communications_manager_im_and_presence_service
10.5\(2\)su2
ciscounified_communications_manager_im_and_presence_service
10.5\(2\)su2a
ciscounified_communications_manager_im_and_presence_service
10.5\(2\)su3
ciscounified_communications_manager_im_and_presence_service
10.5\(2\)su4
ciscounified_communications_manager_im_and_presence_service
10.5\(2\)su4a
ciscounified_communications_manager_im_and_presence_service
10.5\(2a\)
ciscounified_communications_manager_im_and_presence_service
10.5\(2b\)
ciscounified_communications_manager_im_and_presence_service
11.0
ciscounified_communications_manager_im_and_presence_service
11.0\(1\)
ciscounified_communications_manager_im_and_presence_service
11.0\(1\)su1
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su1
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su2
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su3
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su3a
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su4
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su5
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su5a
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su6
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su7
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su8
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su9
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su10
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)su11
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su1
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su2
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su3
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su4
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su5
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su6
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su7
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su8
𝑥
= Vulnerable software versions