SB2021040721 - Information disclosure in Cisco Unified Communications Manager
Published: April 7, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) File and Directory Information Exposure (CVE-ID: CVE-2021-1406)
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper inclusion of sensitive information in downloadable files. A remote authenticated user can issue a set of commands to obtain hashed credentials of system users.
Remediation
Install update from vendor's website.