CVE-2014-8009: Infoleak
Published Dec 10, 2014
·Updated
The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log files, aka Bug ID CSCur99239.
Affected Software
1 affected component
Cisco Unified Computing System<=2.1\(3f\)
Event History
Dec 10, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8009?
CVE-2014-8009 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2014-8009?
To fix CVE-2014-8009, users should upgrade to a version of Cisco Unified Computing System later than 2.1(3f).
3
What type of attack does CVE-2014-8009 allow?
CVE-2014-8009 allows remote attackers to obtain sensitive information by reading log files.
4
What systems are affected by CVE-2014-8009?
CVE-2014-8009 affects Cisco Unified Computing System software versions up to and including 2.1(3f).
5
Is CVE-2014-8009 a remote vulnerability?
Yes, CVE-2014-8009 is a remote vulnerability that can be exploited by attackers without physical access.