5
CVSSv2

CVE-2014-0732

Published: 20/02/2014 Updated: 21/02/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and previous versions does not properly enforce authentication requirements, which allows remote malicious users to read application files via a direct request to a URL, aka Bug ID CSCum46495.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 3.3\\(5\\)sr2a

cisco unified communications manager 4.1\\(3\\)

cisco unified communications manager 4.1\\(3\\)sr1

cisco unified communications manager 4.1\\(3\\)sr2

cisco unified communications manager

cisco unified communications manager 3.3\\(5\\)sr1

cisco unified communications manager 4.1\\(3\\)sr3

cisco unified communications manager 4.2

cisco unified communications manager 4.3

cisco unified communications manager 4.2.2

cisco unified communications manager 4.2.3

cisco unified communications manager 4.2.3sr1

cisco unified communications manager 4.2.3sr2

cisco unified communications manager 10.0

cisco unified communications manager 3.3\\(5\\)

cisco unified communications manager 4.1\\(3\\)sr4

cisco unified communications manager 4.2.1

cisco unified communications manager 4.2.3sr2b

Vendor Advisories

A vulnerability in Real Time Monitoring Tool (RTMT) web application of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to access several files related to the RTMT application The vulnerability is due to insufficient authentication enforcement An attacker could exploit this vulnerability by ...