CVE-2014-7991
published 2014-11-14CVE-2014-7991: The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.68%
48.6th percentile
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Remote Mobile Access Subsystem Vulnerability
vendor_cisco·2014-11-11·CVSS 4.3
CVE-2014-7991 [MEDIUM] CWE-20 Cisco Unified Communications Manager Remote Mobile Access Subsystem Vulnerability
Cisco Unified Communications Manager Remote Mobile Access Subsystem Vulnerability
A vulnerability in the Remote Mobile Access Subsystem in Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to supply a crafted Transport Layer Security (TLS) certificate that may be accepted by the affected device.
The vulnerability is due to improper validation of the SAN field of a TLS certificate. An attacker could exploit this vulnerability by impersonating a VCS core device and supplying a certificate signed by a certificate authority trusted by the Cisco Unified CM that contains crafted values in the SAN field.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may
GHSA
GHSA-pwqj-948j-h8ph: The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-7991 [MEDIUM] GHSA-pwqj-948j-h8ph: The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/62267http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7991http://tools.cisco.com/security/center/viewAlert.x?alertId=36381http://www.securityfocus.com/bid/71013http://www.securitytracker.com/id/1031181https://exchange.xforce.ibmcloud.com/vulnerabilities/98574http://secunia.com/advisories/62267http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7991http://tools.cisco.com/security/center/viewAlert.x?alertId=36381http://www.securityfocus.com/bid/71013http://www.securitytracker.com/id/1031181https://exchange.xforce.ibmcloud.com/vulnerabilities/98574
2014-11-14
Published