HIGH · 9.0

CVE-2014-2197

The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allo...

Vulnerability Description

The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allows remote authenticated users to modify administrative credentials via a crafted URL, aka Bug ID CSCun49862.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoUnified Cdm Application Software<= 8.1
CiscoUnified Communications Domain Manager-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-2197?

CVE-2014-2197 is a vulnerability with a CVSS score of 9.0 (HIGH). The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allo...

How severe is CVE-2014-2197?

CVE-2014-2197 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-2197?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Cdm Application Software, Cisco Unified Communications Domain Manager.