Release date: 2013-02-01
Updated on:
Affected Systems:
Cisco Unity Express <1, 8.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57678
CVE (CAN) ID: CVE-2013-1120
Cisco Unity is an advanced Unified Communication solution for branches and small and medium-sized offices. It provides powerful message sending services and Intelligent Voice Messaging Services.
Earlier versions of Cisco Unity Express 8.0 do not properly verify certain inputs. Unauthorized Remote attackers can send specially crafted requests to perform cross-site request forgery attacks.
<* Source: Jacob Holcomb
Link: http://secunia.com/advisories/52045/
Http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1120
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2013-1120) and patches for this:
CVE-2013-1120: Cisco Unity Express Cross Site Request Forgery Vulnerabilities
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1120