CVE-2014-3300
Viproy CUCDM IP Phone XML Services Call Forwarding Tool
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted URL, aka Bug ID CSCum77041.
El portal BVSMWeb en el Framework web en Cisco Unified Communications Domain Manager (CDM) en Unified CDM Application Software anterior a 10 no implementa debidamente el control de acceso, lo que facilita a atacantes remotos modificar información de usuario a través de una URL manipulada, también conocido como Bug ID CSCum77041.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-05-07 CVE Reserved
- 2014-07-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/59556 | Third Party Advisory | |
http://www.securityfocus.com/bid/68331 | Third Party Advisory | |
http://www.securitytracker.com/id/1030515 | Third Party Advisory | |
- |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unified Cdm Application Software Search vendor "Cisco" for product "Unified Cdm Application Software" | <= 8.1.4 Search vendor "Cisco" for product "Unified Cdm Application Software" and version " <= 8.1.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Cdm Application Software Search vendor "Cisco" for product "Unified Cdm Application Software" | 8.1 Search vendor "Cisco" for product "Unified Cdm Application Software" and version "8.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Communications Domain Manager Search vendor "Cisco" for product "Unified Communications Domain Manager" | - | - |
Affected
|