6.8
CVSSv2

CVE-2014-0740

Published: 27/02/2014 Updated: 01/08/2015
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and previous versions allows remote malicious users to hijack the authentication of administrators for requests that make administrative changes, aka Bug ID CSCun00701.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 4.1\\(3\\)sr4

cisco unified communications manager 4.2

cisco unified communications manager 4.2.1

cisco unified communications manager 4.2.2

cisco unified communications manager

cisco unified communications manager 3.3\\(5\\)

cisco unified communications manager 3.3\\(5\\)sr1

cisco unified communications manager 3.3\\(5\\)sr2a

cisco unified communications manager 4.3

cisco unified communications manager 10.0

cisco unified communications manager 4.1\\(3\\)

cisco unified communications manager 4.1\\(3\\)sr2

cisco unified communications manager 4.2.3sr1

cisco unified communications manager 4.2.3sr2b

cisco unified communications manager 4.1\\(3\\)sr1

cisco unified communications manager 4.1\\(3\\)sr3

cisco unified communications manager 4.2.3

cisco unified communications manager 4.2.3sr2

Vendor Advisories

A vulnerability in the OS Administration page of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack against the OS Administration web interface The vulnerability is due to insufficient CSRF protections on the Call Detail Records (CDR) Analys ...