CVE-2014-3274
published 2014-05-26CVE-2014-3274: Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be established, which allows man-in-the-middle…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.13%
62.6th percentile
Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be established, which allows man-in-the-middle attackers to obtain sensitive directory information by leveraging a network position between CTS and Cisco Unified Communications Manager (UCM) to block HTTPS traffic, aka Bug ID CSCuj26326.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_system_software | <= 6.0.5\(5\) | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5r36-q7mm-42xf: Cisco TelePresence System (CTS) 6
ghsa_unreviewed·2022-05-17
CVE-2014-3274 [MEDIUM] GHSA-5r36-q7mm-42xf: Cisco TelePresence System (CTS) 6
Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be established, which allows man-in-the-middle attackers to obtain sensitive directory information by leveraging a network position between CTS and Cisco Unified Communications Manager (UCM) to block HTTPS traffic, aka Bug ID CSCuj26326.
Cisco
Cisco TelePresence System Directory Information Disclosure Vulnerability
vendor_cisco·2014-05-22·CVSS 4.3
CVE-2014-3274 [MEDIUM] CWE-200 Cisco TelePresence System Directory Information Disclosure Vulnerability
Cisco TelePresence System Directory Information Disclosure Vulnerability
A vulnerability in the code retrieving directory information of Cisco TelePresence System (CTS) could allow an unauthenticated, remote attacker to intercept and read the content of a directory transferred between the CTS and the Cisco Unified Communications Manager (Cisco UCM).
The vulnerability is due to a failure to enforce HTTPS for transferring directory content. An attacker could exploit this vulnerability by blocking the connection over HTTPS between the CTS and Cisco UCM. Because of this vulnerability, the CTS will try to connect to the Cisco UCM via HTTP, which could allow Directory information to be gathered by observing the communication between the CTS and Cisco UCM.
Cisco has confirmed the vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3274http://tools.cisco.com/security/center/viewAlert.x?alertId=34327http://www.securitytracker.com/id/1030272http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3274http://tools.cisco.com/security/center/viewAlert.x?alertId=34327http://www.securitytracker.com/id/1030272
2014-05-26
Published