CVE-2014-3280

CWE-264CWE-7726 documents6 sources
Severity
4.0MEDIUM
EPSS
0.4%
top 39.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3
Latest updateMay 17

Description

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified Administration GUI web page, aka Bug IDs CSCun46045 and CSCun46116.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-v5ch-jpfh-x28g: The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 92022-05-17
GHSA
OpenStack Compute (nova) allows remote authenticated users to cause a denial of service2022-05-14
CVEList
CVE-2014-3280: The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 92014-06-03

📋Vendor Advisories

1
Red Hat
openstack-nova: Deleting instances in resize state fails2015-09-01

💬Community

1
Bugzilla
CVE-2015-3280 openstack-nova: Deleting instances in resize state fails2015-08-28
CVE-2014-3280 (MEDIUM CVSS 4) | The web framework in VOSS in Cisco | cvebase.io