CVE-2014-2198: Critical severity cisco unified communications domain manager platform vulnerability
Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the support and root accounts by extracting this key from a binary file found in a different installation of the product, aka Bug ID CSCud41130.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2198?
CVE-2014-2198 is classified as a high severity vulnerability due to the presence of a hardcoded SSH private key.
How do I fix CVE-2014-2198?
To fix CVE-2014-2198, upgrade to Cisco Unified Communications Domain Manager platform software version 4.4.2 or later.
What systems are affected by CVE-2014-2198?
CVE-2014-2198 affects Cisco Unified Communications Domain Manager versions prior to 4.4.2.
What type of attack can exploit CVE-2014-2198?
CVE-2014-2198 can be exploited by remote attackers who gain access to the hardcoded SSH private key.
Is there a workaround for CVE-2014-2198?
There are no known workarounds for CVE-2014-2198 other than updating to a patched version.