First published: Tue Feb 04 2014(Updated: )
Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCul24917 and CSCul24908.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | <=9.1\(2.10000.28\) | |
Cisco Unified Communications Manager | =9.1\(1\) | |
Cisco Unified Communications Manager | =9.1\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0686 is classified as a medium severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2014-0686, ensure that the affected version of Cisco Unified Communications Manager is updated to the latest version that contains the necessary security patches.
CVE-2014-0686 affects Cisco Unified Communications Manager version 9.1(2.10000.28) and earlier versions, including 9.1(1) and 9.1(2).
CVE-2014-0686 can be exploited by local users who have access to the affected system and can leverage incorrect file permissions.
CVE-2014-0686 is related to a local privilege escalation attack, allowing unauthorized users to gain higher privileges on the system.