7.5
CVSSv2

CVE-2014-0734

Published: 20/02/2014 Updated: 16/09/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and previous versions allows remote malicious users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum46483.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 3.3\\(5\\)sr1

cisco unified communications manager 3.3\\(5\\)sr2a

cisco unified communications manager 4.1\\(3\\)

cisco unified communications manager 4.1\\(3\\)sr1

cisco unified communications manager 4.2.1

cisco unified communications manager 4.2.2

cisco unified communications manager 4.2.3

cisco unified communications manager 4.2.3sr1

cisco unified communications manager

cisco unified communications manager 4.1\\(3\\)sr3

cisco unified communications manager 4.2

cisco unified communications manager 4.2.3sr2

cisco unified communications manager 4.3

cisco unified communications manager 10.0

cisco unified communications manager 3.3\\(5\\)

cisco unified communications manager 4.1\\(3\\)sr2

cisco unified communications manager 4.1\\(3\\)sr4

cisco unified communications manager 4.2.3sr2b

Vendor Advisories

A vulnerability in the Certificate Authority Proxy Function (CAPF) of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to impact the integrity of the system by executing arbitrary SQL queries The vulnerability is due to a failure to validate user-supplied input used in SQL queries An attacke ...