6.2
CVSSv2

CVE-2014-0742

Published: 27/02/2014 Updated: 29/07/2015
CVSS v2 Base Score: 6.2 | Impact Score: 9.2 | Exploitability Score: 3.1
VMScore: 552
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:N

Vulnerability Summary

The Certificate Authority Proxy Function (CAPF) CLI implementation in the CSR management feature in Cisco Unified Communications Manager (Unified CM) 10.0(1) and previous versions allows local users to read or modify arbitrary files via unspecified vectors, aka Bug ID CSCum95464.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 4.1\\(3\\)sr2

cisco unified communications manager 4.1\\(3\\)sr3

cisco unified communications manager 4.1\\(3\\)sr4

cisco unified communications manager 4.2

cisco unified communications manager 4.2.1

cisco unified communications manager 10.0

cisco unified communications manager

cisco unified communications manager 3.3\\(5\\)

cisco unified communications manager 4.2.3sr2b

cisco unified communications manager 4.3

cisco unified communications manager 3.3\\(5\\)sr2a

cisco unified communications manager 4.1\\(3\\)sr1

cisco unified communications manager 4.2.3

cisco unified communications manager 4.2.3sr2

cisco unified communications manager 3.3\\(5\\)sr1

cisco unified communications manager 4.1\\(3\\)

cisco unified communications manager 4.2.2

cisco unified communications manager 4.2.3sr1

Vendor Advisories

A vulnerability in the Certificate Authority Proxy Function (CAPF) command-line function for Certificate Signing Request (CSR) management of Cisco Unified Communications Manager (Cisco Unified CM) could allow an authenticated, local attacker to read or write arbitrary files to the underlying operating system The vulnerability is due to insufficie ...