CVE-2014-0686
published 2014-02-04CVE-2014-0686: Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file…
PriorityP421medium6CVSS 2.0
AVLACHAuSCCICAC
EPSS
0.31%
22.9th percentile
Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCul24917 and CSCul24908.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 9.1\(2.10000.28\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.0MEDIUMAV:L/AC:H/Au:S/C:C/I:C/A:C
vendor_cisco6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7v4h-325x-vg9c: Cisco Unified Communications Manager (aka Unified CM) 9
ghsa_unreviewed·2022-05-14
CVE-2014-0686 [MEDIUM] GHSA-7v4h-325x-vg9c: Cisco Unified Communications Manager (aka Unified CM) 9
Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCul24917 and CSCul24908.
Cisco
Cisco Unified Communications Manager Operating System-Level Privilege Escalation Vulnerability
vendor_cisco·2014-02-03·CVSS 6.0
CVE-2014-0686 [MEDIUM] CWE-264 Cisco Unified Communications Manager Operating System-Level Privilege Escalation Vulnerability
Cisco Unified Communications Manager Operating System-Level Privilege Escalation Vulnerability
A vulnerability in underlying file permissions of specific operating system-level commands of Cisco Unified Communications Manager (Cisco Unified CM) could allow an authenticated, local attacker to gain elevated privileges.
The vulnerability is due to insufficient file permissions. An attacker could exploit this vulnerability by accessing the underlying operating system and manipulating specific command interaction. An exploit could allow the attacker to gain elevated privileges on the Cisco Unified CM node.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must have local access to the targeted
No detection rules found.
No public exploits indexed.
http://osvdb.org/102750http://secunia.com/advisories/56818http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0686http://tools.cisco.com/security/center/viewAlert.x?alertId=32683http://www.securityfocus.com/bid/65281https://exchange.xforce.ibmcloud.com/vulnerabilities/90852http://osvdb.org/102750http://secunia.com/advisories/56818http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0686http://tools.cisco.com/security/center/viewAlert.x?alertId=32683http://www.securityfocus.com/bid/65281https://exchange.xforce.ibmcloud.com/vulnerabilities/90852
2014-02-04
Published