Cisco MediaSense Search and Play Authorization Vulnerability

Related Vulnerabilities: CVE-2014-0672  

A vulnerability in the Search and Play interface of Cisco MediaSense could allow an authenticated, remote attacker to access recordings in the Search and Play interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the Search and Play interface. An exploit could allow the attacker to access recordings in the Search and Play interface. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, an attacker must authenticate to a targeted system. This access requirement reduces the likelihood of a successful exploit.