{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"Cisco Unified Communications Manager versions 6.x ant\u00e9rieures \u00e0 6.1(2).","product":{"name":"Unified Communications Manager","vendor":{"name":"Cisco","scada":false}}},{"description":"Cisco Unified Communications Manager versions 5.x ant\u00e9rieures \u00e0 5.1(3c) ;","product":{"name":"Unified Communications Manager","vendor":{"name":"Cisco","scada":false}}},{"description":"Cisco Unified CallManager versions 4.1 ;","product":{"name":"Unified Communications Manager","vendor":{"name":"Cisco","scada":false}}},{"description":"Cisco Unified Communications Manager versions 4.2 ant\u00e9rieures \u00e0 4.2(3)SR4 ;","product":{"name":"Unified Communications Manager","vendor":{"name":"Cisco","scada":false}}},{"description":"Cisco Unified Communications Manager versions 4.3 ant\u00e9rieures \u00e0 4.3(2)SR1 ;","product":{"name":"Unified Communications Manager","vendor":{"name":"Cisco","scada":false}}}],"affected_systems_content":null,"content":"## Description\n\nDeux vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Cisco Unified\nCommunications Manager (CUCM) :\n\n-   le service Computer Telephony Integration Manager des versions 5.x\n    et 6.x de CUCM ne traite pas correctement certaines donn\u00e9es, ce qui\n    peut conduire \u00e0 un d\u00e9ni de service \u00e0 distance (CVE-2008-2061) ;\n-   l'authentification int\u00e9gr\u00e9e au service Real-Time Information Server\n    Data Collector des versions 4.x, 5.x et 6.x de CUCM peut \u00eatre\n    contourn\u00e9e, ce qui permet d'avoir acc\u00e8s \u00e0 certaines informations\n    confidentielles (CVE-2008-2062 et CVE-2008-2730).\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2008-2061","url":"https://www.cve.org/CVERecord?id=CVE-2008-2061"},{"name":"CVE-2008-2730","url":"https://www.cve.org/CVERecord?id=CVE-2008-2730"},{"name":"CVE-2008-2062","url":"https://www.cve.org/CVERecord?id=CVE-2008-2062"}],"links":[],"reference":"CERTA-2008-AVI-339","revisions":[{"description":"version initiale.","revision_date":"2008-06-26T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service \u00e0 distance"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"}],"summary":"Deux vuln\u00e9rabilit\u00e9s dans <span class=\"textit\">Cisco Unified\nCommunications Manager</span> permettent de r\u00e9aliser un d\u00e9ni de service\n\u00e0 distance et de contourner la politique de s\u00e9curit\u00e9.\n","title":"Vuln\u00e9rabilit\u00e9s dans Cisco Unified Communications Manager","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Cisco 20080625-cucm du 25 juin 2008","url":"http://www.cisco.com/warp/public/707/cisco-sa-20080625-cucm.shtml"}]}
