CVE-2014-7991Improper Input Validation in Cisco Unified Communications Manager

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 47.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 17

Description

The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-pwqj-948j-h8ph: The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 102022-05-17
CVEList
CVE-2014-7991: The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 102014-11-14

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager Remote Mobile Access Subsystem Vulnerability2014-11-11
CVE-2014-7991 — Improper Input Validation in Cisco | cvebase