Lucene search

K
cveCiscoCVE-2014-3338
HistoryAug 12, 2014 - 11:55 p.m.

CVE-2014-3338

2014-08-1223:55:03
CWE-20
cisco
web.nvd.nist.gov
32
cve-2014-3338
cisco
unified communications manager
ctimanager
sso
kerberos
bug id cscum95491
nvd

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.007

Percentile

80.1%

The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO tokens, which allows remote authenticated users to gain privileges and execute arbitrary commands via crafted token data, aka Bug ID CSCum95491.

Affected configurations

Nvd
Node
ciscounified_communications_managerMatch10.0\(1\)
VendorProductVersionCPE
ciscounified_communications_manager10.0(1)cpe:2.3:a:cisco:unified_communications_manager:10.0\(1\):*:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.007

Percentile

80.1%

Related for CVE-2014-3338