Vulnerability Description
The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allows remote authenticated users to modify administrative credentials via a crafted URL, aka Bug ID CSCun49862.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Cdm Application Software | <= 8.1 |
| Cisco | Unified Communications Domain Manager | - |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/59573
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://tools.cisco.com/security/center/viewAMBAlert.x?alertId=34689
- http://www.securityfocus.com/bid/68333
- http://www.securitytracker.com/id/1030515
- http://secunia.com/advisories/59573
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://tools.cisco.com/security/center/viewAMBAlert.x?alertId=34689
- http://www.securityfocus.com/bid/68333
- http://www.securitytracker.com/id/1030515
FAQ
What is CVE-2014-2197?
CVE-2014-2197 is a vulnerability with a CVSS score of 9.0 (HIGH). The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allo...
How severe is CVE-2014-2197?
CVE-2014-2197 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2197?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Cdm Application Software, Cisco Unified Communications Domain Manager.