PT-2014-3752 · Cisco · Cisco Unified Communications Manager

Published

2014-01-08

·

Updated

2017-08-29

·

CVE-2014-0657

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager (Unified CM) versions 9.1(1) and earlier
Description The administration portal in Cisco Unified Communications Manager does not properly handle role restrictions. This allows remote authenticated users to bypass role-based access control by visiting a forbidden portal URL multiple times.
Recommendations For versions 9.1(1) and earlier, update to a version that properly handles role restrictions to prevent bypassing of role-based access control.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0657

Affected Products

Cisco Unified Communications Manager