Lucene search

K
cveCiscoCVE-2014-0724
HistoryFeb 13, 2014 - 5:24 a.m.

CVE-2014-0724

2014-02-1305:24:51
CWE-20
cisco
web.nvd.nist.gov
27
cisco
ucm
cve-2014-0724
remote attackers
authentication bypass
arbitrary files
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

38.1%

The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSCum05340.

Affected configurations

Nvd
Node
ciscounified_communications_managerRange10.0\(1\)
OR
ciscounified_communications_managerMatch10.0
VendorProductVersionCPE
ciscounified_communications_manager*cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*
ciscounified_communications_manager10.0cpe:2.3:a:cisco:unified_communications_manager:10.0:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

38.1%

Related for CVE-2014-0724