Vulnerability Name:

CVE-2014-3300 (CCN-94226)

Assigned:2014-07-02
Published:2014-07-02
Updated:2017-01-12
Summary:The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted URL, aka Bug ID CSCum77041.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
6.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
6.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-264
Vulnerability Consequences:Data Manipulation
References:Source: MITRE
Type: CNA
CVE-2014-3300

Source: SECUNIA
Type: UNKNOWN
59556

Source: CCN
Type: cisco-sa-20140702-cucdm
Multiple Vulnerabilities in Cisco Unified Communications Domain Manager

Source: CISCO
Type: Vendor Advisory
20140702 Multiple Vulnerabilities in Cisco Unified Communications Domain Manager

Source: CISCO
Type: Vendor Advisory
20140702 Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in Cisco Unified Communications Domain Manager

Source: BID
Type: Third Party Advisory, VDB Entry
68331

Source: CCN
Type: BID-68331
Cisco Unified Communications Domain Manager BVSMWeb CVE-2014-3300 Security Bypass Vulnerability

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1030515

Source: XF
Type: UNKNOWN
cisco-ucdm-cve20143300-sec-bypass(94226)

Source: CCN
Type: Rapid7 Vulnerability & Exploit Database
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool

Source: CCN
Type: Rapid7 Vulnerability and Exploit Database [05-30-2018]
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool

Source: CCN
Type: Rapid7 Web site
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool

Source: CCN
Type: Rapid7 Vulnerability and Exploit Database [05-30-2018]
Viproy CUCDM IP Phone XML Services - Speed Dial Attack Tool

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cisco:unified_cdm_application_software:8.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_cdm_application_software:*:*:*:*:*:*:*:* (Version <= 8.1.4)
  • OR cpe:/a:cisco:unified_communications_domain_manager:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco unified cdm application software 8.1
    cisco unified cdm application software *
    cisco unified communications domain manager -