First published: Wed Dec 10 2014(Updated: )
The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Domain Manager Platform | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8010 has a high severity rating, given its ability to allow remote authenticated administrators to execute arbitrary OS commands.
To fix CVE-2014-8010, update to a patched version of Cisco Unified Communications Domain Manager that addresses this vulnerability.
CVE-2014-8010 affects users of Cisco Unified Communications Domain Manager version 8.0.
CVE-2014-8010 is a command injection vulnerability that allows the execution of arbitrary operating system commands.
Yes, CVE-2014-8010 can be exploited remotely by authenticated administrators.