First published: Thu Feb 27 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of administrators for requests that make administrative changes, aka Bug ID CSCun00701.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | <=10.0\(1\) | |
Cisco Unified Communications Manager | =3.3\(5\) | |
Cisco Unified Communications Manager | =3.3\(5\)sr1 | |
Cisco Unified Communications Manager | =3.3\(5\)sr2a | |
Cisco Unified Communications Manager | =4.1\(3\) | |
Cisco Unified Communications Manager | =4.1\(3\)sr1 | |
Cisco Unified Communications Manager | =4.1\(3\)sr2 | |
Cisco Unified Communications Manager | =4.1\(3\)sr3 | |
Cisco Unified Communications Manager | =4.1\(3\)sr4 | |
Cisco Unified Communications Manager | =4.2 | |
Cisco Unified Communications Manager | =4.2.1 | |
Cisco Unified Communications Manager | =4.2.2 | |
Cisco Unified Communications Manager | =4.2.3 | |
Cisco Unified Communications Manager | =4.2.3sr1 | |
Cisco Unified Communications Manager | =4.2.3sr2 | |
Cisco Unified Communications Manager | =4.2.3sr2b | |
Cisco Unified Communications Manager | =4.3 | |
Cisco Unified Communications Manager | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0740 has been rated as high severity due to its potential for unauthorized access and administrative session hijacking.
To mitigate CVE-2014-0740, apply the latest security patches provided by Cisco for the affected versions of Unified Communications Manager.
CVE-2014-0740 affects Cisco Unified Communications Manager versions 10.0(1) and earlier, including several versions in the 3.x and 4.x series.
CVE-2014-0740 is categorized as a cross-site request forgery (CSRF) vulnerability.
Yes, CVE-2014-0740 can be exploited remotely, allowing attackers to hijack the authentication of administrators.