CVE-2014-0733
published 2014-02-20CVE-2014-0733: The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce…
PriorityP335medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.80%
76.0th percentile
The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct request to a URL, aka Bug ID CSCum46494.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Enterprise License Manager Information Disclosure Vulnerability
vendor_cisco·2014-02-19·CVSS 5.0
CVE-2014-0733 [MEDIUM] CWE-200 Cisco Unified Communications Manager Enterprise License Manager Information Disclosure Vulnerability
Cisco Unified Communications Manager Enterprise License Manager Information Disclosure Vulnerability
A vulnerability in the Enterprise License Manager (ELM) of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to access underlying ELM files.
The vulnerability is due to insufficient authentication enforcement. An attacker could exploit this vulnerability by accessing a specific URL related to ELM. An exploit could allow the attacker to access underlying ELM files.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker may need access to trusted, internal network in which the targeted device may reside to access the URL related to EML on the
GHSA
GHSA-8rq5-2qqg-g449: The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-0733 [MEDIUM] CWE-287 GHSA-8rq5-2qqg-g449: The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10
The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct request to a URL, aka Bug ID CSCum46494.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-20
Published