4
CVSSv2

CVE-2014-2185

Published: 29/04/2014 Updated: 29/04/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in Call Detail Records (CDR) Management of Cisco Unified Communications Manager (Cisco Unified CM) could allow an authenticated, remote malicious user to acquire sensitive information. The vulnerability is due to extraneous information included in the web page. An attacker could exploit this vulnerability by accessing the affected web page and extracting the sensitive information about devices configured for CDR use. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager

Vendor Advisories

A vulnerability in Call Detail Records (CDR) Management of Cisco Unified Communications Manager (Cisco Unified CM) could allow an authenticated, remote attacker to acquire sensitive information The vulnerability is due to extraneous information included in the web page An attacker could exploit this vulnerability by accessing the affected web pa ...