CVE-2014-0724: Input Validation
The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSCum05340.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0724?
CVE-2014-0724 is classified as medium severity due to its potential for unauthorized access and information disclosure.
How do I fix CVE-2014-0724?
To fix CVE-2014-0724, upgrade Cisco Unified Communications Manager to version 10.0(2) or later.
What are the potential impacts of CVE-2014-0724?
The potential impacts of CVE-2014-0724 include unauthorized file access and sensitive information exposure.
Who is affected by CVE-2014-0724?
Organizations using Cisco Unified Communications Manager 10.0(1) and earlier are affected by CVE-2014-0724.
Is there a workaround for CVE-2014-0724?
There are no documented workarounds for CVE-2014-0724, so upgrading is the recommended course of action.