CVE-2014-0740
published 2014-02-27CVE-2014-0740: Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.98%
58.6th percentile
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of administrators for requests that make administrative changes, aka Bug ID CSCun00701.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.2 | 2.3.0-1ubuntu3.2 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.0MEDIUM
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4xqj-gmj4-778q: Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component i
ghsa_unreviewed·2022-05-17
CVE-2014-0740 [MEDIUM] CWE-352 GHSA-4xqj-gmj4-778q: Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component i
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of administrators for requests that make administrative changes, aka Bug ID CSCun00701.
OSV
Pillow vulnerabilities
osv·2016-09-27·CVSS 5.0
CVE-2014-9601 Pillow vulnerabilities
Pillow vulnerabilities
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI, Tiff, and PhotoCD files. A remote attacker could use this issue to
cause Pillow to crash, resulting in a denial of service.
(CVE-2016-0740, CVE-2016-0775, CVE-2016-2533)
Cisco
Cisco Unified Communications Manager OS Administration CSRF Vulnerability
vendor_cisco·2014-02-26·CVSS 6.8
CVE-2014-0740 [MEDIUM] CWE-352 Cisco Unified Communications Manager OS Administration CSRF Vulnerability
Cisco Unified Communications Manager OS Administration CSRF Vulnerability
A vulnerability in the OS Administration page of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack against the OS Administration web interface.
The vulnerability is due to insufficient CSRF protections on the Call Detail Records (CDR) Analysis and Reporting (CAR) web interface. An attacker could exploit this vulnerability by persuading an authenticated user of the affected system to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to cause changes to OS Administration on behalf of the user.
Cisco has confirmed the vulnerability in a security notic
No detection rules found.
No public exploits indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0740http://tools.cisco.com/security/center/viewAlert.x?alertId=33049http://www.securitytracker.com/id/1029843http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0740http://tools.cisco.com/security/center/viewAlert.x?alertId=33049http://www.securitytracker.com/id/1029843
2014-02-27
Published