CVE-2014-7991: Medium severity cisco unified communications solutions vulnerability
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7991?
CVE-2014-7991 has been assigned a high severity rating due to the potential for man-in-the-middle attacks.
How do I fix CVE-2014-7991?
To mitigate CVE-2014-7991, upgrade to a version of Cisco Unified Communications Manager later than 10.0(1) that properly validates the Subject Alternative Name field.
What devices are affected by CVE-2014-7991?
CVE-2014-7991 affects Cisco Unified Communications Manager versions 10.0(1) and earlier.
What impact does CVE-2014-7991 have on system security?
CVE-2014-7991 allows attackers to exploit improper validation in X.509 certificates, potentially leading to unauthorized access and data interception.
Can CVE-2014-7991 be exploited remotely?
Yes, CVE-2014-7991 can be exploited remotely by man-in-the-middle attackers using crafted certificates.