CVE-2014-3274

Severity
4.3MEDIUM
EPSS
0.4%
top 40.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateMay 17

Description

Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be established, which allows man-in-the-middle attackers to obtain sensitive directory information by leveraging a network position between CTS and Cisco Unified Communications Manager (UCM) to block HTTPS traffic, aka Bug ID CSCuj26326.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-5r36-q7mm-42xf: Cisco TelePresence System (CTS) 62022-05-17
CVEList
CVE-2014-3274: Cisco TelePresence System (CTS) 62014-05-23

📋Vendor Advisories

1
Cisco
Cisco TelePresence System Directory Information Disclosure Vulnerability2014-05-22
CVE-2014-3274 (MEDIUM CVSS 4.3) | Cisco TelePresence System (CTS) 6.0 | cvebase.io