Inclusion of Sensitive Information in Log Files in Cisco Systems, Inc products - CVE-2021-1226

 

Inclusion of Sensitive Information in Log Files in Cisco Systems, Inc products - CVE-2021-1226

Published: January 13, 2021 / Updated: January 19, 2021


Vulnerability identifier: #VU49596
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1226
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software stores sensitive information into log files within the audit logging component. A remote authenticated attacker can read the log files and gain access to sensitive data.


Affected software

Unified Communications Manager (CallManager)
Cisco Unified Communications Manager Session Management Edition
Cisco Prime License Manager
Cisco Unified Communications Manager IM & Presence Service
Cisco Emergency Responder
Cisco Unity Connection

How to mitigate CVE-2021-1226

Install updates from vendor's website.

Unified Communications Manager (CallManager) - addressed in versions 11.5.1 SU9, 12.0.1 SU4, 12.5.1 SU3
Cisco Prime License Manager - update to 11.5.1 SU9
Cisco Unified Communications Manager Session Management Edition - addressed in versions 11.5.1 SU9, 12.0.1 SU4, 12.5.1 SU3
Cisco Unified Communications Manager IM & Presence Service - addressed in versions 11.5.1 SU9, 12.5.1 SU3
Cisco Emergency Responder - update to 12.5.1 SU3
Cisco Unity Connection - addressed in versions 11.5.1 SU9, 12.0.1 SU4, 12.5.1 SU3

External References

Related Security Bulletins