First published: Thu Feb 13 2014(Updated: )
The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSCum05340.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | <=10.0\(1\) | |
Cisco Unified Communications Manager | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0724 is classified as medium severity due to its potential for unauthorized access and information disclosure.
To fix CVE-2014-0724, upgrade Cisco Unified Communications Manager to version 10.0(2) or later.
The potential impacts of CVE-2014-0724 include unauthorized file access and sensitive information exposure.
Organizations using Cisco Unified Communications Manager 10.0(1) and earlier are affected by CVE-2014-0724.
There are no documented workarounds for CVE-2014-0724, so upgrading is the recommended course of action.