Cisco Unified Communications Manager CVE-2014-0724 Arbitrary File Disclosure Vulnerability
BID:65497
Info
Cisco Unified Communications Manager CVE-2014-0724 Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 65497 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0724 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2014 12:00AM |
| Updated: | Feb 11 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Unified Communications Manager (UCM) 0 |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager CVE-2014-0724 Arbitrary File Disclosure Vulnerability
Cisco Unified Communications Manager is prone to an arbitrary file disclosure vulnerability.
An attacker can exploit this issue to view arbitrary files from the local filesystem within the context of the affected application. This may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCum05340.
Cisco Unified Communications Manager is prone to an arbitrary file disclosure vulnerability.
An attacker can exploit this issue to view arbitrary files from the local filesystem within the context of the affected application. This may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCum05340.
Exploit / POC
Cisco Unified Communications Manager CVE-2014-0724 Arbitrary File Disclosure Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
Cisco Unified Communications Manager CVE-2014-0724 Arbitrary File Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified Communications Manager CVE-2014-0724 Arbitrary File Disclosure Vulnerability
References:
References: