製品・ソフトウェアに関する情報
シスコシステムズの Cisco Unified Communications Manager IM and Presence Service における情報漏えいに関する脆弱性
Title シスコシステムズの Cisco Unified Communications Manager IM and Presence Service における情報漏えいに関する脆弱性
Summary

シスコシステムズの Cisco Unified Communications Manager IM and Presence Service には、情報漏えいに関する脆弱性が存在します。

Possible impacts 情報を取得される可能性があります。 
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date Nov. 6, 2024, midnight
Registration Date Aug. 8, 2025, 5:18 p.m.
Last Update Aug. 8, 2025, 5:18 p.m.
CVSS3.0 : 警告
Score 6.5
Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected System
シスコシステムズ
Cisco Unified Communications Manager IM and Presence Service 10.0(1)
Cisco Unified Communications Manager IM and Presence Service 10.0(1)su1
Cisco Unified Communications Manager IM and Presence Service 10.0(1)su2
Cisco Unified Communications Manager IM and Presence Service 10.5(1)
Cisco Unified Communications Manager IM and Presence Service 10.5(1)su1
Cisco Unified Communications Manager IM and Presence Service 10.5(1)su2
Cisco Unified Communications Manager IM and Presence Service 10.5(1)su3
Cisco Unified Communications Manager IM and Presence Service 10.5(2)
Cisco Unified Communications Manager IM and Presence Service 10.5(2)su1
Cisco Unified Communications Manager IM and Presence Service 10.5(2)su2
Cisco Unified Communications Manager IM and Presence Service 10.5(2)su2a
Cisco Unified Communications Manager IM and Presence Service 10.5(2)su3
Cisco Unified Communications Manager IM and Presence Service 10.5(2)su4
Cisco Unified Communications Manager IM and Presence Service 10.5(2)su4a
Cisco Unified Communications Manager IM and Presence Service 10.5(2a)
Cisco Unified Communications Manager IM and Presence Service 10.5(2b)
Cisco Unified Communications Manager IM and Presence Service 11.0
Cisco Unified Communications Manager IM and Presence Service 11.0(1)
Cisco Unified Communications Manager IM and Presence Service 11.0(1)su1
Cisco Unified Communications Manager IM and Presence Service 11.5(1)
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
1 [2025年08月08日]   掲載 Aug. 8, 2025, 3:31 p.m.

NVD Vulnerability Information
CVE-2024-20457
Summary

A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.

This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to access sensitive information from the device.

Publication Date Nov. 7, 2024, 2:15 a.m.
Registration Date Nov. 7, 2024, 5 a.m.
Last Update Nov. 7, 2024, 3:17 a.m.
Related information, measures and tools
Common Vulnerabilities List