CVE-2014-0724
published 2014-02-13CVE-2014-0724: The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read…
PriorityP431medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.03%
60.2th percentile
The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSCum05340.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Arbitrary File Read Vulnerability
vendor_cisco·2014-02-12·CVSS 4.0
CVE-2014-0724 [MEDIUM] CWE-20 Cisco Unified Communications Manager Arbitrary File Read Vulnerability
Cisco Unified Communications Manager Arbitrary File Read Vulnerability
A vulnerability in the bulk administration interface of Cisco Unified Communications Manager (UCM) could allow an authenticated, remote attacker to read arbitrary files from the underlying file system.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by providing crafted input at a specific prompt in the bulk administration interface. An exploit could allow the attacker to read arbitrary files from the underlying operating system.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases the likeli
GHSA
GHSA-5m93-68wm-7pmv: The bulk administration interface in Cisco Unified Communications Manager (UCM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-0724 [MEDIUM] CWE-20 GHSA-5m93-68wm-7pmv: The bulk administration interface in Cisco Unified Communications Manager (UCM) 10
The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSCum05340.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-13
Published