CVE-2014-7991
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.
El subsistema de acceso remoto móvil en Cisco Unified Communications Manager (CM) 10.0(1) y anteriores no valida correctamente el campo 'Subject Alternative Name' (SAN) de un certificado X.509, lo que permite a atacantes man-in.the-middle engañar el núcleo de los dispositivos VCS a través de un certificado manipulado por una Autoridad Certificadora, también conocido como ID CSCuq86376.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-08 CVE Reserved
- 2014-11-14 CVE Published
- 2024-06-26 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/62267 | Third Party Advisory | |
http://www.securityfocus.com/bid/71013 | Vdb Entry | |
http://www.securitytracker.com/id/1031181 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98574 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7991 | 2017-09-08 | |
http://tools.cisco.com/security/center/viewAlert.x?alertId=36381 | 2017-09-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unified Communications Manager Search vendor "Cisco" for product "Unified Communications Manager" | <= 10.0\(1\) Search vendor "Cisco" for product "Unified Communications Manager" and version " <= 10.0\(1\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Communications Manager Search vendor "Cisco" for product "Unified Communications Manager" | 10.0 Search vendor "Cisco" for product "Unified Communications Manager" and version "10.0" | - |
Affected
|