Cisco Unified Communications Manager CVE-2014-3292 Multiple Arbitrary File Access Vulnerabilities
BID:67982
Info
Cisco Unified Communications Manager CVE-2014-3292 Multiple Arbitrary File Access Vulnerabilities
| Bugtraq ID: | 67982 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3292 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2014 12:00AM |
| Updated: | Jun 09 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Unified Communications Manager 10.0(1) |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager CVE-2014-3292 Multiple Arbitrary File Access Vulnerabilities
Cisco Unified Communications Manager is prone to an multiple arbitrary file-access vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to download or delete arbitrary files, which may aid in further attacks.
These issues are being tracked by Cisco Bug ID CSCuo17302 and CSCuo17199.
Cisco Unified Communications Manager is prone to an multiple arbitrary file-access vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to download or delete arbitrary files, which may aid in further attacks.
These issues are being tracked by Cisco Bug ID CSCuo17302 and CSCuo17199.