CVE-2014-3280
published 2014-06-03CVE-2014-3280: The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows…
PriorityP419medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.03%
78.8th percentile
The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified Administration GUI web page, aka Bug IDs CSCun46045 and CSCun46116.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | <= 9.0\(.1\) | — |
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager | — | — |
| openstack | nova | >= 0 < 2014.2.4 | 2014.2.4 |
| openstack | nova | >= 2015.1.0 < 2015.1.2 | 2015.1.2 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5ch-jpfh-x28g: The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9
ghsa_unreviewed·2022-05-17
CVE-2014-3280 [MEDIUM] GHSA-v5ch-jpfh-x28g: The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9
The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified Administration GUI web page, aka Bug IDs CSCun46045 and CSCun46116.
GHSA
OpenStack Compute (nova) allows remote authenticated users to cause a denial of service
ghsa·2022-05-14
CVE-2015-3280 [MEDIUM] OpenStack Compute (nova) allows remote authenticated users to cause a denial of service
OpenStack Compute (nova) allows remote authenticated users to cause a denial of service
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.
Red Hat
openstack-nova: Deleting instances in resize state fails
vendor_redhat·2015-09-01·CVSS 6.8
CVE-2015-3280 [MEDIUM] CWE-772 openstack-nova: Deleting instances in resize state fails
openstack-nova: Deleting instances in resize state fails
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.
A flaw was found in the way OpenStack Compute (nova) handled the resize state. If an authenticated user deleted an instance while it was in the resize state, it could cause the original instance to not be deleted from the compute node it was running on, allowing the user to cause a denial of service.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/58400http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3280http://tools.cisco.com/security/center/viewAlert.x?alertId=34379http://www.securityfocus.com/bid/67661http://www.securitytracker.com/id/1030306http://secunia.com/advisories/58400http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3280http://tools.cisco.com/security/center/viewAlert.x?alertId=34379http://www.securityfocus.com/bid/67661http://www.securitytracker.com/id/1030306
2014-06-03
Published