SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3333

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka…

HIGH 9.0EPSS 3.13%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.

CVSS 2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
3.13% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
cisco/unity connection
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.