CVE-2014-8010: Input Validation
Published Dec 10, 2014
·Updated
The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.
Affected Software
1 affected component
Cisco Unified Communications Domain Manager=8.0
Event History
Dec 10, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8010?
CVE-2014-8010 has a high severity rating, given its ability to allow remote authenticated administrators to execute arbitrary OS commands.
2
How do I fix CVE-2014-8010?
To fix CVE-2014-8010, update to a patched version of Cisco Unified Communications Domain Manager that addresses this vulnerability.
3
Who is affected by CVE-2014-8010?
CVE-2014-8010 affects users of Cisco Unified Communications Domain Manager version 8.0.
4
What type of vulnerability is CVE-2014-8010?
CVE-2014-8010 is a command injection vulnerability that allows the execution of arbitrary operating system commands.
5
Can CVE-2014-8010 be exploited remotely?
Yes, CVE-2014-8010 can be exploited remotely by authenticated administrators.