Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-7991

Опубликовано: 14 нояб. 2014
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*
Версия до 10.0\(1\) (включая)
cpe:2.3:a:cisco:unified_communications_manager:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00292
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
больше 3 лет назад

The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.

EPSS

Процентиль: 52%
0.00292
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310