CVE-2013-7030 EXPLOIT
7.3
HIGH · CVSS 3.1 · EPSS 5.2% (pctl 92)
Patch early
A public exploit exists.
Description
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue
Scoring
| CVSS | 7.3 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L |
| EPSS | 5.17% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-310 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-12-12 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| cisco | unified communications manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco Unified Communications Manager - TFTP Service | 2013-12-12 |
References
→ the Explorer · watch your stack · NVD