Cisco Unity Connection contains a vulnerability that may allow an authenticated, remote attacker with privilege of the Help Desk Administrator role to elevate privileges and obtain full access to the affected system.
Vulnerable Systems:
* Cisco Unity Connection version 7.1 and Prior
Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Administrator role, aka Bug ID CSCtd45141.
Vendor Status:
Cisco has released free software updates that address this vulnerability.