HIGH · 10.0

CVE-2014-2198

Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the supp...

Vulnerability Description

Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the support and root accounts by extracting this key from a binary file found in a different installation of the product, aka Bug ID CSCud41130.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoUnified Cdm Platform Software<= 4.4
CiscoUnified Communications Domain Manager-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-2198?

CVE-2014-2198 is a vulnerability with a CVSS score of 10.0 (HIGH). Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the supp...

How severe is CVE-2014-2198?

CVE-2014-2198 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-2198?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Cdm Platform Software, Cisco Unified Communications Domain Manager.