CVE-2014-0657
Last modified
CVE-2014-0657 is a vulnerability of currently unknown severity. The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role restrictions, which allows remote authenticated users to bypass role-based access control via multiple visits to a forbidden portal URL, aka Bug ID CSCuj83540.. EPSS estimates a 2.13% chance of exploitation in the next 30 days.
Description
The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role restrictions, which allows remote authenticated users to bypass role-based access control via multiple visits to a forbidden portal URL, aka Bug ID CSCuj83540.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Communications Manager | <= 9.1\(1\) |
| Cisco | Unified Communications Manager | 3.3\(5\) |
| Cisco | Unified Communications Manager | 3.3\(5\)sr1 |
| Cisco | Unified Communications Manager | 3.3\(5\)sr2a |
| Cisco | Unified Communications Manager | 4.1\(3\) |
| Cisco | Unified Communications Manager | 4.1\(3\)sr1 |
| Cisco | Unified Communications Manager | 4.1\(3\)sr2 |
| Cisco | Unified Communications Manager | 4.1\(3\)sr3 |
| Cisco | Unified Communications Manager | 4.1\(3\)sr4 |
| Cisco | Unified Communications Manager | 4.2 |
| Cisco | Unified Communications Manager | 4.2.1 |
| Cisco | Unified Communications Manager | 4.2.2 |
| Cisco | Unified Communications Manager | 4.2.3 |
| Cisco | Unified Communications Manager | 4.2.3sr1 |
| Cisco | Unified Communications Manager | 4.2.3sr2 |
| Cisco | Unified Communications Manager | 4.2.3sr2b |
| Cisco | Unified Communications Manager | 4.3 |
| Cisco | Unified Communications Manager | 4.3\(1\) |
| Cisco | Unified Communications Manager | 5.0 |
| Cisco | Unified Communications Manager | 5.1 |
| Cisco | Unified Communications Manager | 5.1\(1\) |
| Cisco | Unified Communications Manager | 5.1\(1b\) |
| Cisco | Unified Communications Manager | 5.1\(1c\) |
| Cisco | Unified Communications Manager | 5.1\(2\) |
| Cisco | Unified Communications Manager | 5.1\(2a\) |
| Cisco | Unified Communications Manager | 5.1\(2b\) |
| Cisco | Unified Communications Manager | 5.1\(3\) |
| Cisco | Unified Communications Manager | 5.1\(3a\) |
| Cisco | Unified Communications Manager | 5.1\(3c\) |
| Cisco | Unified Communications Manager | 5.1\(3d\) |
| Cisco | Unified Communications Manager | 5.1\(3e\) |
| Cisco | Unified Communications Manager | 5.1.2 |
| Cisco | Unified Communications Manager | 6.0 |
| Cisco | Unified Communications Manager | 6.0\(1\) |
| Cisco | Unified Communications Manager | 6.0\(1a\) |
| Cisco | Unified Communications Manager | 6.0\(1b\) |
| Cisco | Unified Communications Manager | 6.1\(1\) |
| Cisco | Unified Communications Manager | 6.1\(1a\) |
| Cisco | Unified Communications Manager | 6.1\(1b\) |
| Cisco | Unified Communications Manager | 6.1\(2\) |
| Cisco | Unified Communications Manager | 6.1\(2\)su1 |
| Cisco | Unified Communications Manager | 6.1\(2\)su1a |
| Cisco | Unified Communications Manager | 6.1\(3\) |
| Cisco | Unified Communications Manager | 6.1\(3a\) |
| Cisco | Unified Communications Manager | 6.1\(3b\) |
| Cisco | Unified Communications Manager | 6.1\(3b\)su1 |
| Cisco | Unified Communications Manager | 6.1\(4\) |
| Cisco | Unified Communications Manager | 6.1\(4\)su1 |
| Cisco | Unified Communications Manager | 6.1\(4a\) |
| Cisco | Unified Communications Manager | 6.1\(4a\)su2 |
Showing 50 of 113 affected configurations. See NVD for the full list.
References
- http://www.securityfocus.com/bid/64690Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029571Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/64690Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029571Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0657?
How severe is CVE-2014-0657?
How do I fix CVE-2014-0657?
Are you affected by CVE-2014-0657?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
