CVE-2014-3338Improper Input Validation in Cisco Unified Communications Manager

Severity
8.5HIGHNVD
EPSS
1.7%
top 17.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 17

Description

The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO tokens, which allows remote authenticated users to gain privileges and execute arbitrary commands via crafted token data, aka Bug ID CSCum95491.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 6.8 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-r9g7-hffm-mwgg: The CTIManager module in Cisco Unified Communications Manager (CM) 102022-05-17
CVEList
CVE-2014-3338: The CTIManager module in Cisco Unified Communications Manager (CM) 102014-08-12

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager CTIManager Vulnerability2014-08-11
CVE-2014-3338 — Improper Input Validation in Cisco | cvebase