Vulnerability Name: | CVE-2014-3333 (CCN-95135) | ||||||||
Assigned: | 2014-08-06 | ||||||||
Published: | 2014-08-06 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3333 Source: SECUNIA Type: UNKNOWN 59768 Source: CCN Type: Cisco Security Notice Cisco Unity Connection HTTP Intercept Vulnerability Source: CISCO Type: Vendor Advisory 20140806 Cisco Unity Connection HTTP Intercept Vulnerability Source: CONFIRM Type: Vendor Advisory http://tools.cisco.com/security/center/viewAlert.x?alertId=35200 Source: BID Type: UNKNOWN 69074 Source: CCN Type: BID-69074 Cisco Unity Connection CVE-2014-3333 Remote Security Vulnerability Source: SECTRACK Type: UNKNOWN 1030688 Source: XF Type: UNKNOWN cisco-unity-cve20143333-priv-esc(95135) Source: XF Type: UNKNOWN cisco-unity-cve20143333-priv-esc(95135) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |