CVE-2014-0731
published 2014-02-22CVE-2014-0731: The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read…
PriorityP337medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.90%
77.4th percentile
The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files via a direct request, aka Bug ID CSCum46497.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2rvc-939c-p372: The administration interface in Cisco Unified Communications Manager (Unified CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-0731 [MEDIUM] GHSA-2rvc-939c-p372: The administration interface in Cisco Unified Communications Manager (Unified CM) 10
The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files via a direct request, aka Bug ID CSCum46497.
Cisco
Cisco Unified Communications Manager Java Class File Availability Vulnerability
vendor_cisco·2014-02-19·CVSS 5.0
CVE-2014-0731 [MEDIUM] CWE-200 Cisco Unified Communications Manager Java Class File Availability Vulnerability
Cisco Unified Communications Manager Java Class File Availability Vulnerability
A vulnerability in the administration interface of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to access Java class files.
The vulnerability is due to insufficient authentication enforcement. An attacker could exploit this vulnerability by accessing a specific URL of the UCM administrative interface. An exploit could allow the attacker to access Java class files that are part of the UCM interface.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker may need access to trusted, internal networks in which the targeted device may reside to access the URL re
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-22
Published