Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco TelePresence System Directory Information Disclosure Vulnerability

Cisco-SA-20140522-CVE-2014-3274 · Medium · Published · Updated

A vulnerability in the code retrieving directory information of Cisco TelePresence System (CTS) could allow an unauthenticated, remote attacker to intercept and read the content of a directory transferred between the CTS and the Cisco Unified Communications Manager (Cisco UCM). The vulnerability is due to a failure to enforce HTTPS for transferring directory content. An attacker could exploit this vulnerability by blocking the connection over HTTPS between the CTS and Cisco UCM. Because of this vulnerability, the CTS will try to connect to the Cisco UCM via HTTP, which could allow Directory information to be gathered by observing the communication between the CTS and Cisco UCM. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, it is likely that an attacker may need access to trusted, internal networks in which a targeted device and the Cisco UCM reside to attempt to block the connection over HTTPS between the two devices. This access requirement would likely reduce the likelihood of a success exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-3274
Cisco Bug IDsCSCuj26326
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:F/RL:OF/RC:C
Product Names From Source
Cisco TelePresence System Software

Related Products

Product CVE Evidence
Cisco Unified Communications Manager CVE-2014-3274 Cisco OpenVuln
Cisco TelePresence System Software CVE-2014-3274 Cisco OpenVuln
Cisco TelePresence CVE-2014-3274 Cisco OpenVuln