CVE-2014-8010
published 2014-12-10CVE-2014-8010: The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted…
PriorityP339medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.50%
71.3th percentile
The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Domain Manager Blind Command Injection Vulnerability
vendor_cisco·2014-12-12·CVSS 6.5
CVE-2014-8010 [MEDIUM] CWE-78 Cisco Unified Communications Domain Manager Blind Command Injection Vulnerability
Cisco Unified Communications Domain Manager Blind Command Injection Vulnerability
A vulnerability in the web framework of Cisco Unified Communications Domain Manager Application Software version 8 could allow an authenticated, remote attacker to inject commands that can be executed by the underlying operating system with the privileges of the web server process.
The vulnerability is due to insufficient input validation when the user sets some values in the user interface. An attacker could exploit this vulnerability by logging in to the system and injecting malicious commands. An exploit could allow the attacker to execute commands remotely with the privileges of the web server process. Administrative credentials are needed to exploit this issue.
Cisco has confirmed the vulnerability in
GHSA
GHSA-c3qw-8xrq-mhcj: The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via cra
ghsa_unreviewed·2022-05-17
CVE-2014-8010 [MEDIUM] CWE-20 GHSA-c3qw-8xrq-mhcj: The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via cra
The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-12-10
Published