VDB
CVE-2022-20752
CVE-2022-20752
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exploit this vulnerability by observing the time it takes the system to respond to various queries. A successful exploit could allow the attacker to determine a sensitive system password.
EPSS 1.01% · 60.9th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
1.01%
60.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | unity_connection | 12.5\(1\), 14.0 |
| Cisco | Cisco Unified Communications Manager | * |
| cisco | unified_communications_manager | 12.5\(1\), 12.5\(1\), 14.0 |
Timeline
- Jul 6, 2022 CVE Published
- Jul 7, 2022 EPSS Score
- Aug 25, 2022 EPSS Score
- Oct 11, 2022 EPSS Score
- Nov 28, 2022 EPSS Score
- Jan 14, 2023 EPSS Score
- Mar 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 19, 2023 EPSS Score
- Jul 23, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Oct 26, 2023 EPSS Score