CVE-2014-3316
published 2014-07-10CVE-2014-3316: The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.80%
76.3th percentile
The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSCup76297.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager DNA Arbitrary File Upload Vulnerability
vendor_cisco·2014-07-10·CVSS 4.0
CVE-2014-3316 [MEDIUM] CWE-20 Cisco Unified Communications Manager DNA Arbitrary File Upload Vulnerability
Cisco Unified Communications Manager DNA Arbitrary File Upload Vulnerability
A vulnerability in the Multiple Analyzer of the Cisco Unified Communications Manager Dialed Number Analyzer (DNA) could allow an authenticated, remote attacker to upload arbitrary files to a restricted location on the filesystem.
The vulnerability is due to insufficient parameter validation. An attacker could exploit this vulnerability by submitting crafted data to the web server.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
Although an attacker must authenticate to an affected device to exploit this vulnerability, the attacker may be able to convince an authenticated user to click a malicious link by using misleading language and instructions.
Cisc
GHSA
GHSA-h4r6-7hxq-5fc9: The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypas
ghsa_unreviewed·2022-05-17
CVE-2014-3316 [MEDIUM] CWE-20 GHSA-h4r6-7hxq-5fc9: The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypas
The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSCup76297.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/59730http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3316http://tools.cisco.com/security/center/viewAlert.x?alertId=34899http://www.securityfocus.com/bid/68479http://www.securitytracker.com/id/1030554https://exchange.xforce.ibmcloud.com/vulnerabilities/94429http://secunia.com/advisories/59730http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3316http://tools.cisco.com/security/center/viewAlert.x?alertId=34899http://www.securityfocus.com/bid/68479http://www.securitytracker.com/id/1030554https://exchange.xforce.ibmcloud.com/vulnerabilities/94429
2014-07-10
Published