4
CVE-2014-3280
- EPSS 2.03%
- Veröffentlicht 03.06.2014 04:44:49
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified Administration GUI web page, aka Bug IDs CSCun46045 and CSCun46116.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Unified Communications Domain Manager Version <= 9.0\(.1\)
Cisco ≫ Unified Communications Domain Manager Version 7.4
Cisco ≫ Unified Communications Domain Manager Version 8.6
Cisco ≫ Unified Communications Domain Manager Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.03% | 0.785 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
http://secunia.com/advisories/58400
http://www.securitytracker.com/id/1030306
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3280
http://tools.cisco.com/security/center/viewAlert.x?alertId=34379
http://www.securityfocus.com/bid/67661