4
CVSSv2

CVE-2014-0657

Published: 08/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and previous versions does not properly handle role restrictions, which allows remote authenticated users to bypass role-based access control via multiple visits to a forbidden portal URL, aka Bug ID CSCuj83540.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 4.1\\(3\\)sr3

cisco unified communications manager 4.1\\(3\\)sr4

cisco unified communications manager 4.2

cisco unified communications manager 4.3

cisco unified communications manager 4.3\\(1\\)

cisco unified communications manager 5.1\\(2a\\)

cisco unified communications manager 5.1\\(2b\\)

cisco unified communications manager 6.0

cisco unified communications manager 6.0\\(1\\)

cisco unified communications manager 6.0\\(1a\\)

cisco unified communications manager 6.1\\(2\\)su1a

cisco unified communications manager 6.1\\(3\\)

cisco unified communications manager 6.1\\(4a\\)su2

cisco unified communications manager 6.1\\(5\\)

cisco unified communications manager 7.0\\(2a\\)su1

cisco unified communications manager 7.0\\(2a\\)su2

cisco unified communications manager 7.1\\(3a\\)su1

cisco unified communications manager 7.1\\(3a\\)su1a

cisco unified communications manager 7.1\\(5a\\)

cisco unified communications manager 7.1\\(5b\\)

cisco unified communications manager 8.0

cisco unified communications manager 8.0\\(1\\)

cisco unified communications manager 8.0\\(3a\\)

cisco unified communications manager 8.0\\(3a\\)su1

cisco unified communications manager 8.5\\(1\\)su3

cisco unified communications manager 8.5\\(1\\)su4

cisco unified communications manager 8.6\\(2a\\)su2

cisco unified communications manager 8.6\\(2a\\)su3

cisco unified communications manager 3.3\\(5\\)

cisco unified communications manager 3.3\\(5\\)sr1

cisco unified communications manager 4.2.1

cisco unified communications manager 4.2.2

cisco unified communications manager 5.0

cisco unified communications manager 5.1

cisco unified communications manager 5.1\\(3\\)

cisco unified communications manager 5.1\\(3a\\)

cisco unified communications manager 6.0\\(1b\\)

cisco unified communications manager 6.1\\(1\\)

cisco unified communications manager 6.1\\(3a\\)

cisco unified communications manager 6.1\\(3b\\)

cisco unified communications manager 6.1\\(5\\)su1

cisco unified communications manager 6.1\\(5\\)su2

cisco unified communications manager 7.1\\(2a\\)

cisco unified communications manager 7.1\\(2a\\)su1

cisco unified communications manager 7.1\\(3b\\)

cisco unified communications manager 7.1\\(3b\\)su1

cisco unified communications manager 7.1\\(5b\\)su1

cisco unified communications manager 7.1\\(5b\\)su1a

cisco unified communications manager 8.0\\(2\\)

cisco unified communications manager 8.0\\(2a\\)

cisco unified communications manager 8.0\\(3a\\)su2

cisco unified communications manager 8.0\\(3a\\)su3

cisco unified communications manager 8.5\\(1\\)su5

cisco unified communications manager 8.6

cisco unified communications manager 8.6\\(1\\)

cisco unified communications manager 8.6\\(3\\)

cisco unified communications manager 8.6\\(4\\)

cisco unified communications manager 3.3\\(5\\)sr2a

cisco unified communications manager 4.1\\(3\\)

cisco unified communications manager 4.2.3

cisco unified communications manager 4.2.3sr1

cisco unified communications manager 5.1\\(1\\)

cisco unified communications manager 5.1\\(1b\\)

cisco unified communications manager 5.1\\(3c\\)

cisco unified communications manager 5.1\\(3d\\)

cisco unified communications manager 6.1\\(1a\\)

cisco unified communications manager 6.1\\(1b\\)

cisco unified communications manager 6.1\\(3b\\)su1

cisco unified communications manager 6.1\\(4\\)

cisco unified communications manager 6.1\\(5\\)su3

cisco unified communications manager 7.0\\(1\\)su1

cisco unified communications manager 7.1\\(2b\\)

cisco unified communications manager 7.1\\(2b\\)su1

cisco unified communications manager 7.1\\(3b\\)su2

cisco unified communications manager 7.1\\(5\\)

cisco unified communications manager 7.1\\(5b\\)su2

cisco unified communications manager 7.1\\(5b\\)su3

cisco unified communications manager 7.1\\(5b\\)su4

cisco unified communications manager 8.0\\(2b\\)

cisco unified communications manager 8.0\\(2c\\)

cisco unified communications manager 8.5

cisco unified communications manager 8.5\\(1\\)

cisco unified communications manager 8.6\\(1a\\)

cisco unified communications manager 8.6\\(2\\)

cisco unified communications manager 9.0\\(1\\)

cisco unified communications manager

cisco unified communications manager 4.1\\(3\\)sr1

cisco unified communications manager 4.1\\(3\\)sr2

cisco unified communications manager 4.2.3sr2

cisco unified communications manager 4.2.3sr2b

cisco unified communications manager 5.1\\(1c\\)

cisco unified communications manager 5.1\\(2\\)

cisco unified communications manager 5.1\\(3e\\)

cisco unified communications manager 5.1.2

cisco unified communications manager 6.1\\(2\\)

cisco unified communications manager 6.1\\(2\\)su1

cisco unified communications manager 6.1\\(4\\)su1

cisco unified communications manager 6.1\\(4a\\)

cisco unified communications manager 7.0\\(1\\)su1a

cisco unified communications manager 7.0\\(2\\)

cisco unified communications manager 7.0\\(2a\\)

cisco unified communications manager 7.1\\(3\\)

cisco unified communications manager 7.1\\(3a\\)

cisco unified communications manager 7.1\\(5\\)su1

cisco unified communications manager 7.1\\(5\\)su1a

cisco unified communications manager 7.1\\(5b\\)su5

cisco unified communications manager 7.1\\(5b\\)su6

cisco unified communications manager 8.0\\(2c\\)su1

cisco unified communications manager 8.0\\(3\\)

cisco unified communications manager 8.5\\(1\\)su1

cisco unified communications manager 8.5\\(1\\)su2

cisco unified communications manager 8.6\\(2a\\)

cisco unified communications manager 8.6\\(2a\\)su1

Vendor Advisories

A vulnerability in the administration portal of Cisco Unified Communications Manager (Unified CM) could allow an authenticated, remote attacker to bypass role restrictions The vulnerability is due to insufficient role restriction processing An attacker could exploit this vulnerability by revisiting the link to a previously denied location of the ...