CVE Vulnerabilities

CVE-2014-3280

Published: Jun 03, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified Administration GUI web page, aka Bug IDs CSCun46045 and CSCun46116.

Affected Software

NameVendorStart VersionEnd Version
Unified_communications_domain_managerCisco*9.0(.1) (including)
Unified_communications_domain_managerCisco7.4 (including)7.4 (including)
Unified_communications_domain_managerCisco8.6 (including)8.6 (including)
Unified_communications_domain_managerCisco8.6(.2) (including)8.6(.2) (including)
Unified_communications_domain_managerCisco9.0 (including)9.0 (including)

References