CVE-2014-3320
Last modified
CVE-2014-3320 is a vulnerability of currently unknown severity. Multiple open redirect vulnerabilities in the admin web interface in the web framework in Cisco Unified Communications Domain Manager (CDM) 8.1(.4) and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted URLs for unspecified scripts, aka Bug ID CSCuo48835.. EPSS estimates a 2.21% chance of exploitation in the next 30 days.
Description
Multiple open redirect vulnerabilities in the admin web interface in the web framework in Cisco Unified Communications Domain Manager (CDM) 8.1(.4) and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted URLs for unspecified scripts, aka Bug ID CSCuo48835.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Communications Domain Manager | <= 8.1\(.4\) |
| Cisco | Unified Communications Domain Manager | 8.1 |
| Cisco | Unified Communications Domain Manager | 8.1\(.1\) |
| Cisco | Unified Communications Domain Manager | 8.1\(.2\) |
| Cisco | Unified Communications Domain Manager | 8.1\(.3\) |
References
- http://www.securityfocus.com/bid/68694Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030613Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/68694Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030613Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3320?
How severe is CVE-2014-3320?
How do I fix CVE-2014-3320?
Are you affected by CVE-2014-3320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
