Lucene search

K
cveCiscoCVE-2014-2180
HistoryApr 29, 2014 - 10:37 a.m.

CVE-2014-2180

2014-04-2910:37:03
CWE-20
cisco
web.nvd.nist.gov
22
cisco
unified contact center express
document management
cve-2014-2180
nvd
bug id cscun74133

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

35.4%

The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.

Affected configurations

Nvd
Node
ciscounified_contact_center_enterprise
OR
ciscounified_contact_center_express_editor_softwareMatch-
VendorProductVersionCPE
ciscounified_contact_center_enterprise*cpe:2.3:a:cisco:unified_contact_center_enterprise:*:*:*:*:*:*:*:*
ciscounified_contact_center_express_editor_software-cpe:2.3:a:cisco:unified_contact_center_express_editor_software:-:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

35.4%

Related for CVE-2014-2180