Vulnerability Name:
CVE-2014-0731 (CCN-91188)
Assigned:
2014-02-18
Published:
2014-02-18
Updated:
2016-09-09
Summary:
The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files via a direct request, aka Bug ID CSCum46497.
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
3.7 Low
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
5.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
3.7 Low
(CCN Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
Vulnerability Type:
CWE-264
Vulnerability Consequences:
Obtain Information
References:
Source: MITRE
Type: CNA
CVE-2014-0731
Source: CCN
Type: Cisco Security Notice
Cisco Unified Communications Manager Java Class File Availability Vulnerability
Source: CISCO
Type: Vendor Advisory
20140218 Cisco Unified Communications Manager Java Class File Availability Vulnerability
Source: CONFIRM
Type: Vendor Advisory
http://tools.cisco.com/security/center/viewAlert.x?alertId=32915
Source: CCN
Type: BID-65644
Cisco Unified Communications Java Class File Information Disclosure Vulnerability
Source: XF
Type: UNKNOWN
cisco-ucm-cve20140731-info-disc(91188)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:cisco:unified_communications_manager:3.3(5):*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:3.3(5)sr1:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:3.3(5)sr2a:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.1(3):*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.1(3)sr1:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.1(3)sr2:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.1(3)sr3:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.1(3)sr4:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.2:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.2.1:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.2.2:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.2.3:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.2.3sr1:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.2.3sr2:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.2.3sr2b:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:4.3:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:10.0:*:*:*:*:*:*:*
OR
cpe:/a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*
(Version <= 10.0(1))
Denotes that component is vulnerable
BACK
cisco
unified communications manager 3.3(5)
cisco
unified communications manager 3.3(5)sr1
cisco
unified communications manager 3.3(5)sr2a
cisco
unified communications manager 4.1(3)
cisco
unified communications manager 4.1(3)sr1
cisco
unified communications manager 4.1(3)sr2
cisco
unified communications manager 4.1(3)sr3
cisco
unified communications manager 4.1(3)sr4
cisco
unified communications manager 4.2
cisco
unified communications manager 4.2.1
cisco
unified communications manager 4.2.2
cisco
unified communications manager 4.2.3
cisco
unified communications manager 4.2.3sr1
cisco
unified communications manager 4.2.3sr2
cisco
unified communications manager 4.2.3sr2b
cisco
unified communications manager 4.3
cisco
unified communications manager 10.0
cisco
unified communications manager *