Cisco Unified Communications Manager Multiple Vulnerabilities
Last Update Date:
27 Aug 2014
Release Date:
13 Aug 2014
3973
Views
RISK: Medium Risk
TYPE: Clients - Im, Chat & Voip
Multiple vulnerabilities were identified in Cisco Unified Communications Manager. A remote authenticated user can cause denial of service conditions and execute arbitrary commands on the target system.
- A remote authenticated user on a registered endpoint can send specially crafted XML data via SIP to cause the target process to crash.
- A remote authenticated user can send specially crafted Kerberos single sign-on (SSO) token data to exploit a flaw in the CTIManager module and execute arbitrary commands with elevated privileges.
Systems with the Cisco CTIManager enabled and configured for single sign-on are affected.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Cisco Unified Communications Manager
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix:
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3337
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3338
Vulnerability Identifier
Source
Related Link
Share with