First published: Fri Nov 14 2014(Updated: )
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | <=10.0\(1\) | |
Cisco Unified Communications Manager | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7991 has been assigned a high severity rating due to the potential for man-in-the-middle attacks.
To mitigate CVE-2014-7991, upgrade to a version of Cisco Unified Communications Manager later than 10.0(1) that properly validates the Subject Alternative Name field.
CVE-2014-7991 affects Cisco Unified Communications Manager versions 10.0(1) and earlier.
CVE-2014-7991 allows attackers to exploit improper validation in X.509 certificates, potentially leading to unauthorized access and data interception.
Yes, CVE-2014-7991 can be exploited remotely by man-in-the-middle attackers using crafted certificates.