CVE-2014-3279
N/A
N/A
Summary
The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSCun39631 and CSCun39643.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securitytracker.com/id/1030306
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3279
- http://secunia.com/advisories/58657
- http://www.securityfocus.com/bid/67663
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34381
- http://secunia.com/advisories/58400
References
- http://www.securitytracker.com/id/1030306
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3279
- http://secunia.com/advisories/58657
- http://www.securityfocus.com/bid/67663
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34381
- http://secunia.com/advisories/58400
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.