CVE-2014-0740: CSRF
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of administrators for requests that make administrative changes, aka Bug ID CSCun00701.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0740?
CVE-2014-0740 has been rated as high severity due to its potential for unauthorized access and administrative session hijacking.
How do I fix CVE-2014-0740?
To mitigate CVE-2014-0740, apply the latest security patches provided by Cisco for the affected versions of Unified Communications Manager.
Which Cisco Unified Communications Manager versions are affected by CVE-2014-0740?
CVE-2014-0740 affects Cisco Unified Communications Manager versions 10.0(1) and earlier, including several versions in the 3.x and 4.x series.
What type of vulnerability is CVE-2014-0740?
CVE-2014-0740 is categorized as a cross-site request forgery (CSRF) vulnerability.
Can CVE-2014-0740 be exploited remotely?
Yes, CVE-2014-0740 can be exploited remotely, allowing attackers to hijack the authentication of administrators.