Cisco MediaSense Search and Play Authorization Vulnerability

Cisco-SA-20140122-CVE-2014-0672 · Medium · Published · Updated

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

A vulnerability in the Search and Play interface of Cisco MediaSense could allow an authenticated, remote attacker to access recordings in the Search and Play interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the Search and Play interface. An exploit could allow the attacker to access recordings in the Search and Play interface. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, an attacker must authenticate to a targeted system. This access requirement reduces the likelihood of a successful exploit.

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-0672
Cisco Bug IDsCSCum16755
CVSS ScoreBase 4.0
Base 4.0 AV:N/AC:L/Au:S/C:P/I:N/A:N/E:H/RL:U/RC:C

Products with public affected evidence