CVE-2014-3338
published 2014-08-12CVE-2014-3338: The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO tokens…
PriorityP353high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
3.12%
86.5th percentile
The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO tokens, which allows remote authenticated users to gain privileges and execute arbitrary commands via crafted token data, aka Bug ID CSCum95491.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r9g7-hffm-mwgg: The CTIManager module in Cisco Unified Communications Manager (CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-3338 [HIGH] CWE-20 GHSA-r9g7-hffm-mwgg: The CTIManager module in Cisco Unified Communications Manager (CM) 10
The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO tokens, which allows remote authenticated users to gain privileges and execute arbitrary commands via crafted token data, aka Bug ID CSCum95491.
Cisco
Cisco Unified Communications Manager CTIManager Vulnerability
vendor_cisco·2014-08-11·CVSS 8.5
CVE-2014-3338 [HIGH] CWE-78 Cisco Unified Communications Manager CTIManager Vulnerability
Cisco Unified Communications Manager CTIManager Vulnerability
A vulnerability in the CTIManager module of Cisco Unified Communications Manager (Cisco Unified CM) could allow an authenticated, remote attacker to execute arbitrary commands with elevated privileges.
The vulnerability is due to a failure to properly validate input contained within Kerberos single sign-on (SSO) tokens. This vulnerability is only exposed when the Cisco CTIManager is enabled and single sign-on has been configured.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must have authenticated access to the targeted device. This access requirement may reduce the likelihood of a successful exploit.
Cisco indicates through the CVSS sc
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/60054http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3338http://tools.cisco.com/security/center/viewAlert.x?alertId=35258http://www.securityfocus.com/bid/69176http://www.securitytracker.com/id/1030710https://exchange.xforce.ibmcloud.com/vulnerabilities/95246http://secunia.com/advisories/60054http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3338http://tools.cisco.com/security/center/viewAlert.x?alertId=35258http://www.securityfocus.com/bid/69176http://www.securitytracker.com/id/1030710https://exchange.xforce.ibmcloud.com/vulnerabilities/95246
2014-08-12
Published