CVE-2014-0743
published 2014-02-27CVE-2014-0743: The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.38%
69.3th percentile
The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, aka Bug ID CSCum95468.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager CAPF Unauthenticated Device Information Update Vulnerability
vendor_cisco·2014-02-25·CVSS 5.0
CVE-2014-0743 [MEDIUM] CWE-287 Cisco Unified Communications Manager CAPF Unauthenticated Device Information Update Vulnerability
Cisco Unified Communications Manager CAPF Unauthenticated Device Information Update Vulnerability
A vulnerability in the Certificate Authority Proxy Function (CAPF) of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to change information related to registered devices.
The vulnerability is due to insufficient authentication enforcement. An attacker could exploit this vulnerability by submitting crafted information regarding the device to CAPF. An exploit could allow the attacker to change certain information regarding a registered device.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
Cisco indicates through the CVSS score that functional exploit code exists; however, the c
GHSA
GHSA-98mx-wqjg-hhx2: The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-0743 [MEDIUM] CWE-287 GHSA-98mx-wqjg-hhx2: The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10
The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, aka Bug ID CSCum95468.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0743http://tools.cisco.com/security/center/viewAlert.x?alertId=33044http://www.securitytracker.com/id/1029843http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0743http://tools.cisco.com/security/center/viewAlert.x?alertId=33044http://www.securitytracker.com/id/1029843
2014-02-27
Published