CVE-2014-3300
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted URL, aka Bug ID CSCum77041.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 21.88% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/unified cdm application software · cisco/unified communications domain manager
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/59556
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140702-cucdmVendor Advisory
- http://tools.cisco.com/security/center/viewAMBAlert.x?alertId=34689Vendor Advisory
- http://www.securityfocus.com/bid/68331Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030515Third Party Advisory, VDB Entry
- http://secunia.com/advisories/59556
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140702-cucdmVendor Advisory
- http://tools.cisco.com/security/center/viewAMBAlert.x?alertId=34689Vendor Advisory
- http://www.securityfocus.com/bid/68331Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030515Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.