PT-2014-8363 · Cisco · Cisco Unified Communications Manager

Published

2014-11-14

·

Updated

2017-09-08

·

CVE-2014-7991

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager versions prior to 10.0(1)
Description The issue is related to the Remote Mobile Access Subsystem, which does not properly validate the Subject Alternative Name field of an X.509 certificate. This allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority.
Recommendations For versions prior to 10.0(1), update to a version that properly validates the Subject Alternative Name field of X.509 certificates to prevent man-in-the-middle attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7991

Affected Products

Cisco Unified Communications Manager