| Vulnerability Name: | CVE-2014-2197 (CCN-94225) | ||||||||
| Assigned: | 2014-07-02 | ||||||||
| Published: | 2014-07-02 | ||||||||
| Updated: | 2017-01-07 | ||||||||
| Summary: | The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allows remote authenticated users to modify administrative credentials via a crafted URL, aka Bug ID CSCun49862. | ||||||||
| CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2014-2197 Source: SECUNIA Type: UNKNOWN 59573 Source: CCN Type: cisco-sa-20140702-cucdm Multiple Vulnerabilities in Cisco Unified Communications Domain Manager Source: CISCO Type: Vendor Advisory 20140702 Multiple Vulnerabilities in Cisco Unified Communications Domain Manager Source: CISCO Type: UNKNOWN 20140702 Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in Cisco Unified Communications Domain Manager Source: BID Type: UNKNOWN 68333 Source: CCN Type: BID-68333 Cisco Unified Communications Domain Manager CVE-2014-2197 Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1030515 Source: XF Type: UNKNOWN cisco-ucdm-cve20142197-priv-esc(94225) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||