VulnerabilityModified
CVE-2014-0672
The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows remote authenticated users to download arbitrary recordings via a request to this interface.
MEDIUM 4.0EPSS 2.09%
Does this matter?
Lower severity and a low EPSS score (2.09%). Track it; it rarely justifies an emergency change on its own.
Description
The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows remote authenticated users to download arbitrary recordings via a request to this interface.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 2.09% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/mediasense
- Source
- psirt@cisco.com
References
- http://osvdb.org/102342Broken Link
- http://secunia.com/advisories/56600Permissions Required
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0672Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32516Vendor Advisory
- http://www.securityfocus.com/bid/65054Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029668Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90616
- http://osvdb.org/102342Broken Link
- http://secunia.com/advisories/56600Permissions Required
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0672Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32516Vendor Advisory
- http://www.securityfocus.com/bid/65054Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029668Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90616
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.