CVE-2013-3433

medium
Published 2013-07-18 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02276.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130717-cucm

Application impact

VendorProductVersionsFixed
cisco ciscounified_communications_manager7.1\(2a\)
cisco ciscounified_communications_manager7.1\(2a\)su1
cisco ciscounified_communications_manager7.1\(2b\)
cisco ciscounified_communications_manager7.1\(2b\)su1
cisco ciscounified_communications_manager7.1\(3\)
cisco ciscounified_communications_manager7.1\(3a\)
cisco ciscounified_communications_manager7.1\(3a\)su1
cisco ciscounified_communications_manager7.1\(3a\)su1a
cisco ciscounified_communications_manager7.1\(3b\)
cisco ciscounified_communications_manager7.1\(3b\)su1
cisco ciscounified_communications_manager7.1\(3b\)su2
cisco ciscounified_communications_manager7.1\(5\)
cisco ciscounified_communications_manager7.1\(5\)su1
cisco ciscounified_communications_manager7.1\(5\)su1a
cisco ciscounified_communications_manager7.1\(5a\)
cisco ciscounified_communications_manager7.1\(5b\)
cisco ciscounified_communications_manager7.1\(5b\)su1
cisco ciscounified_communications_manager7.1\(5b\)su1a
cisco ciscounified_communications_manager7.1\(5b\)su2
cisco ciscounified_communications_manager7.1\(5b\)su3
cisco ciscounified_communications_manager7.1\(5b\)su4
cisco ciscounified_communications_manager7.1\(5b\)su5
cisco ciscounified_communications_manager7.1\(5b\)su6
cisco ciscounified_communications_manager8.0
cisco ciscounified_communications_manager8.0\(1\)
cisco ciscounified_communications_manager8.0\(2\)
cisco ciscounified_communications_manager8.0\(2a\)
cisco ciscounified_communications_manager8.0\(2b\)
cisco ciscounified_communications_manager8.0\(2c\)
cisco ciscounified_communications_manager8.0\(2c\)su1
cisco ciscounified_communications_manager8.0\(3\)
cisco ciscounified_communications_manager8.0\(3a\)
cisco ciscounified_communications_manager8.0\(3a\)su1
cisco ciscounified_communications_manager8.0\(3a\)su2
cisco ciscounified_communications_manager8.0\(3a\)su3
cisco ciscounified_communications_manager8.5
cisco ciscounified_communications_manager8.5\(1\)
cisco ciscounified_communications_manager8.5\(1\)su1
cisco ciscounified_communications_manager8.5\(1\)su2
cisco ciscounified_communications_manager8.5\(1\)su3
cisco ciscounified_communications_manager8.5\(1\)su4
cisco ciscounified_communications_manager8.5\(1\)su5
cisco ciscounified_communications_manager8.6
cisco ciscounified_communications_manager8.6\(1\)
cisco ciscounified_communications_manager8.6\(1a\)
cisco ciscounified_communications_manager8.6\(2\)
cisco ciscounified_communications_manager8.6\(2a\)
cisco ciscounified_communications_manager8.6\(2a\)su1
cisco ciscounified_communications_manager8.6\(2a\)su2
cisco ciscounified_communications_manager8.6\(2a\)su3
cisco ciscounified_communications_manager8.6\(3\)
cisco ciscounified_communications_manager8.6\(4\)
cisco ciscounified_communications_manager9.0\(1\)
cisco ciscounified_communications_manager9.1\(1\)
cisco ciscounified_communications_manager9.1\(1a\)
cisco ciscounified_communications_manager9.1.1\(a\)

References

Verify integrity in audit chain (admin only). AS-IS.