CVE-2013-3434

medium
Published 2013-07-18 · Modified 2026-04-29
CVSS v3
VIR risk
6.8

Description

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02242.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
cisco ciscounified_communications_manager7.1\(2a\)
cisco ciscounified_communications_manager7.1\(2a\)su1
cisco ciscounified_communications_manager7.1\(2b\)
cisco ciscounified_communications_manager7.1\(2b\)su1
cisco ciscounified_communications_manager7.1\(3\)
cisco ciscounified_communications_manager7.1\(3a\)
cisco ciscounified_communications_manager7.1\(3a\)su1
cisco ciscounified_communications_manager7.1\(3a\)su1a
cisco ciscounified_communications_manager7.1\(3b\)
cisco ciscounified_communications_manager7.1\(3b\)su1
cisco ciscounified_communications_manager7.1\(3b\)su2
cisco ciscounified_communications_manager7.1\(5\)
cisco ciscounified_communications_manager7.1\(5\)su1
cisco ciscounified_communications_manager7.1\(5\)su1a
cisco ciscounified_communications_manager7.1\(5a\)
cisco ciscounified_communications_manager7.1\(5b\)
cisco ciscounified_communications_manager7.1\(5b\)su1
cisco ciscounified_communications_manager7.1\(5b\)su1a
cisco ciscounified_communications_manager7.1\(5b\)su2
cisco ciscounified_communications_manager7.1\(5b\)su3
cisco ciscounified_communications_manager7.1\(5b\)su4
cisco ciscounified_communications_manager7.1\(5b\)su5
cisco ciscounified_communications_manager7.1\(5b\)su6
cisco ciscounified_communications_manager8.0
cisco ciscounified_communications_manager8.0\(1\)
cisco ciscounified_communications_manager8.0\(2\)
cisco ciscounified_communications_manager8.0\(2a\)
cisco ciscounified_communications_manager8.0\(2b\)
cisco ciscounified_communications_manager8.0\(2c\)
cisco ciscounified_communications_manager8.0\(2c\)su1
cisco ciscounified_communications_manager8.0\(3\)
cisco ciscounified_communications_manager8.0\(3a\)
cisco ciscounified_communications_manager8.0\(3a\)su1
cisco ciscounified_communications_manager8.0\(3a\)su2
cisco ciscounified_communications_manager8.0\(3a\)su3
cisco ciscounified_communications_manager8.5
cisco ciscounified_communications_manager8.5\(1\)
cisco ciscounified_communications_manager8.5\(1\)su1
cisco ciscounified_communications_manager8.5\(1\)su2
cisco ciscounified_communications_manager8.5\(1\)su3
cisco ciscounified_communications_manager8.5\(1\)su4
cisco ciscounified_communications_manager8.5\(1\)su5
cisco ciscounified_communications_manager8.6
cisco ciscounified_communications_manager8.6\(1\)
cisco ciscounified_communications_manager8.6\(1a\)
cisco ciscounified_communications_manager8.6\(2\)
cisco ciscounified_communications_manager8.6\(2a\)
cisco ciscounified_communications_manager8.6\(2a\)su1
cisco ciscounified_communications_manager8.6\(2a\)su2
cisco ciscounified_communications_manager8.6\(2a\)su3
cisco ciscounified_communications_manager8.6\(3\)
cisco ciscounified_communications_manager8.6\(4\)
cisco ciscounified_communications_manager9.0\(1\)
cisco ciscounified_communications_manager9.1\(1\)
cisco ciscounified_communications_manager9.1\(1a\)
cisco ciscounified_communications_manager9.1.1\(a\)

References

💬 Discuss CVE-2013-3434 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.