CVE-2014-3333
The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 3.13% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/unity connection
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/59768
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=35200Vendor Advisory
- http://www.securityfocus.com/bid/69074
- http://www.securitytracker.com/id/1030688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95135
- http://secunia.com/advisories/59768
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=35200Vendor Advisory
- http://www.securityfocus.com/bid/69074
- http://www.securitytracker.com/id/1030688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95135
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.