CVE-2014-3332
published 2014-08-11CVE-2014-3332: Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions setting, which allows remote authenticated users to establish…
PriorityP422medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.64%
73.9th percentile
Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions setting, which allows remote authenticated users to establish undetected concurrent logins via unspecified vectors, aka Bug ID CSCup98029.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 8.6\(2\) | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv6.9MEDIUM
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Concurrent Login Vulnerability
vendor_cisco·2014-08-07·CVSS 4.0
CVE-2014-3332 [MEDIUM] Cisco Unified Communications Manager Concurrent Login Vulnerability
Cisco Unified Communications Manager Concurrent Login Vulnerability
A vulnerability in the CLI restrictions setting of Cisco Unified Communications Manager could allow an authenticated, remote attacker to remain undetected as an authenticated user. The vulnerability is due to improper sanitization of authenticated users.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must have authenticated access to a targeted system. This access requirement may decrease the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
GHSA
GHSA-hr6h-cw97-w8v6: Cisco Unified Communications Manager (CM) 8
ghsa_unreviewed·2022-05-17
CVE-2014-3332 [MEDIUM] GHSA-hr6h-cw97-w8v6: Cisco Unified Communications Manager (CM) 8
Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions setting, which allows remote authenticated users to establish undetected concurrent logins via unspecified vectors, aka Bug ID CSCup98029.
OSV
linux-lts-utopic vulnerabilities
osv·2015-05-20·CVSS 6.9
CVE-2014-9710 linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A memory corruption issue was discovered in AES decryption when using the
Intel AES-NI accelerated code path. A remote attacker could exploit this
flaw to cause a denial of service (system crash) or potentially escalate
privileges on Intel base machines with AEC-GCM mode IPSec security
association. (CVE-2015-3331)
A flaw was discovered in the Linux kernel's IPv4 networking when using TCP
fast open to initiate a connection. An unprivileged local user could
exploit this flaw to cause a denial of service (system crash).
(CVE-2015-3332)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3332http://tools.cisco.com/security/center/viewAlert.x?alertId=35198http://www.securityfocus.com/bid/69068http://www.securitytracker.com/id/1030687https://exchange.xforce.ibmcloud.com/vulnerabilities/95136http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3332http://tools.cisco.com/security/center/viewAlert.x?alertId=35198http://www.securityfocus.com/bid/69068http://www.securitytracker.com/id/1030687https://exchange.xforce.ibmcloud.com/vulnerabilities/95136
2014-08-11
Published