AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-0632

HIGH · CVSS 9 EPSS 3.02%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-03-12 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 9.0. It affects Cisco. It may be remotely exploitable.

CVE
CVE-2009-0632
Severity
HIGH
CVSS
9
EPSS
3.02%
Cisco

Original NVD Description

The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.