{"api_version":"1","generated_at":"2026-07-23T00:57:52+00:00","cve":"CVE-2014-3333","urls":{"html":"https://cve.report/CVE-2014-3333","api":"https://cve.report/api/cve/CVE-2014-3333.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-3333","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-3333"},"summary":{"title":"CVE-2014-3333","description":"The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an \"HTTP Intercept\" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.","state":"PUBLISHED","assigner":"cisco","published_at":"2014-08-11 20:55:07","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333","name":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Unity Connection HTTP Intercept Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95135","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95135","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/59768","name":"http://secunia.com/advisories/59768","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030688","name":"http://www.securitytracker.com/id/1030688","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Unity Connection Lets Remote Authenticated Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=35200","name":"http://tools.cisco.com/security/center/viewAlert.x?alertId=35200","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Unity Connection HTTP Intercept Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/69074","name":"http://www.securityfocus.com/bid/69074","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-3333","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3333","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"3333","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"unity_connection","cpe6":"9.1\\(1\\)","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"3333","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"unity_connection","cpe6":"9.1\\(2\\)","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:43:05.167Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"cisco-unity-cve20143333-priv-esc(95135)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95135"},{"name":"20140806 Cisco Unity Connection HTTP Intercept Vulnerability","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333"},{"name":"59768","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/59768"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=35200"},{"name":"69074","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/69074"},{"name":"1030688","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030688"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-08-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an \"HTTP Intercept\" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"name":"cisco-unity-cve20143333-priv-esc(95135)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95135"},{"name":"20140806 Cisco Unity Connection HTTP Intercept Vulnerability","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333"},{"name":"59768","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/59768"},{"tags":["x_refsource_CONFIRM"],"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=35200"},{"name":"69074","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/69074"},{"name":"1030688","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030688"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","ID":"CVE-2014-3333","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an \"HTTP Intercept\" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"cisco-unity-cve20143333-priv-esc(95135)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95135"},{"name":"20140806 Cisco Unity Connection HTTP Intercept Vulnerability","refsource":"CISCO","url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333"},{"name":"59768","refsource":"SECUNIA","url":"http://secunia.com/advisories/59768"},{"name":"http://tools.cisco.com/security/center/viewAlert.x?alertId=35200","refsource":"CONFIRM","url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=35200"},{"name":"69074","refsource":"BID","url":"http://www.securityfocus.com/bid/69074"},{"name":"1030688","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030688"}]}}}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2014-3333","datePublished":"2014-08-11T20:00:00.000Z","dateReserved":"2014-05-07T00:00:00.000Z","dateUpdated":"2024-08-06T10:43:05.167Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-08-11 20:55:07","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:unity_connection:9.1\\(1\\):*:*:*:*:*:*:*","matchCriteriaId":"50CD06E4-0C09-4DD7-B106-56DC680CE333"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:unity_connection:9.1\\(2\\):*:*:*:*:*:*:*","matchCriteriaId":"BA2751A8-A3CF-4CC7-A7F2-003165C1AEDB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"3333","Ordinal":"1","Title":"CVE-2014-3333","CVE":"CVE-2014-3333","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"3333","Ordinal":"1","NoteData":"The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an \"HTTP Intercept\" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.","Type":"Description","Title":"CVE-2014-3333"},{"CveYear":"2014","CveId":"3333","Ordinal":"2","NoteData":"2014-08-11","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"3333","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}