CVE-2014-3333
published 2014-08-11CVE-2014-3333: The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack…
PriorityP343critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
3.13%
86.3th percentile
The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-434r-4m9g-54qc: The server in Cisco Unity Connection 9
ghsa_unreviewed·2022-05-17
CVE-2014-3333 [HIGH] GHSA-434r-4m9g-54qc: The server in Cisco Unity Connection 9
The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.
Cisco
Cisco Unity Connection HTTP Intercept Vulnerability
vendor_cisco·2014-08-07·CVSS 9.0
CVE-2014-3333 [CRITICAL] CWE-264 Cisco Unity Connection HTTP Intercept Vulnerability
Cisco Unity Connection HTTP Intercept Vulnerability
A vulnerability in Cisco Unity Connection Server could allow an authenticated, remote attacker to elevate privileges and obtain full access to the affected system. The vulnerability is due to improper privilege escalation. An attacker may be able to exploit this vulnerability by reading files accessible to the web server user.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement may reduce the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/59768http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333http://tools.cisco.com/security/center/viewAlert.x?alertId=35200http://www.securityfocus.com/bid/69074http://www.securitytracker.com/id/1030688https://exchange.xforce.ibmcloud.com/vulnerabilities/95135http://secunia.com/advisories/59768http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333http://tools.cisco.com/security/center/viewAlert.x?alertId=35200http://www.securityfocus.com/bid/69074http://www.securitytracker.com/id/1030688https://exchange.xforce.ibmcloud.com/vulnerabilities/95135
2014-08-11
Published