First published: Thu May 29 2014(Updated: )
Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCun79731.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Domain Manager | <=9.0\(.1\) | |
Cisco Unified Communications Domain Manager | =7.4 | |
Cisco Unified Communications Domain Manager | =8.6 | |
Cisco Unified Communications Domain Manager | =8.6\(.2\) | |
Cisco Unified Communications Domain Manager | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3283 is considered a medium severity vulnerability due to its potential for abuse in phishing attacks.
To fix CVE-2014-3283, upgrade to a version of Cisco Unified Communications Domain Manager that is not affected, specifically versions later than 9.0(.1).
CVE-2014-3283 can facilitate arbitrary redirection attacks allowing attackers to redirect users to malicious websites.
CVE-2014-3283 affects versions 9.0(.1) and earlier, as well as specific versions 7.4 and 8.6 of the Cisco Unified Communications Domain Manager.
CVE-2014-3283 is a known vulnerability that affects various deployments of Cisco's Unified Communications Domain Manager, making it of particular concern for organizations using this software.