CVE-2014-0747
published 2014-02-27CVE-2014-0747: The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users…
PriorityP420medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.25%
16.6th percentile
The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to inject commands via unspecified CAPF programs, aka Bug ID CSCum95493.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pr76-46qc-55q8: The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-0747 [MEDIUM] CWE-20 GHSA-pr76-46qc-55q8: The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10
The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to inject commands via unspecified CAPF programs, aka Bug ID CSCum95493.
Cisco
Cisco Unified Communications Manager CAPF CLI Command Injection Vulnerability
vendor_cisco·2014-02-26·CVSS 6.8
CVE-2014-0747 [MEDIUM] CWE-78 Cisco Unified Communications Manager CAPF CLI Command Injection Vulnerability
Cisco Unified Communications Manager CAPF CLI Command Injection Vulnerability
A vulnerability in the Certificate Authority Proxy Function (CAPF) command-line interface (CLI) of Cisco Unified Communications Manager (Cisco Unified CM) could allow an authenticated, local attacker to inject commands into the underlying operating system.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into certain CAPF commands. An exploit could allow the attacker to perform operations on the underlying operating system.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker would need local access to the targeted device. This access requ
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0747http://tools.cisco.com/security/center/viewAlert.x?alertId=33048http://www.securitytracker.com/id/1029843http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0747http://tools.cisco.com/security/center/viewAlert.x?alertId=33048http://www.securitytracker.com/id/1029843
2014-02-27
Published