Cisco Unified Communications Manager TLS Certificate Validation Security Bypass Vulnerability
BID:71013
Info
Cisco Unified Communications Manager TLS Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 71013 |
| Class: | Design Error |
| CVE: |
CVE-2014-7991 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2014 12:00AM |
| Updated: | Nov 12 2014 12:58AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager TLS Certificate Validation Security Bypass Vulnerability
Cisco Unified Communications Manager is prone to a security-bypass vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCuq86376.
Cisco Unified Communications Manager is prone to a security-bypass vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCuq86376.
Exploit / POC
Cisco Unified Communications Manager TLS Certificate Validation Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Cisco Unified Communications Manager TLS Certificate Validation Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified Communications Manager TLS Certificate Validation Security Bypass Vulnerability
References:
References:
- Cisco Homepage (Cisco)