CVE-2014-0747: Input Validation
The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to inject commands via unspecified CAPF programs, aka Bug ID CSCum95493.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0747?
CVE-2014-0747 has been rated as a critical vulnerability due to its potential for command injection by local users.
How do I fix CVE-2014-0747?
To remediate CVE-2014-0747, upgrade your Cisco Unified Communications Manager to a version later than 10.0(1) that is not affected by this vulnerability.
What are the affected versions in CVE-2014-0747?
CVE-2014-0747 affects Cisco Unified Communications Manager versions up to and including 10.0(1) and various earlier 3.x, 4.x series versions.
Who is impacted by CVE-2014-0747?
Local users of Cisco Unified Communications Manager who have access privileges may be impacted by CVE-2014-0747.
What type of vulnerability is CVE-2014-0747?
CVE-2014-0747 is classified as a command injection vulnerability in the CAPF CLI implementation.