ID

VAR-201401-0362


CVE

CVE-2014-0656


TITLE

Cisco Context Directory Agent Vulnerabilities triggered by missing user interface data

Trust: 0.8

sources: JVNDB: JVNDB-2014-001014

DESCRIPTION

Cisco Context Directory Agent (CDA) allows remote authenticated users to trigger the omission of certain user-interface data via crafted field values, aka Bug ID CSCuj45353. An attacker can exploit this issue to hide values from displaying in the CDA user interface. This may also aid in launching further attacks. Cisco Context Directory Agent (CDA) is a set of Cisco (Cisco) company running on Cisco Linux machines for real-time monitoring Active Directory Domain Controller (DC) authentication and other related events. A security vulnerability exists in Cisco CDA

Trust: 1.98

sources: NVD: CVE-2014-0656 // JVNDB: JVNDB-2014-001014 // BID: 64701 // VULHUB: VHN-68149

AFFECTED PRODUCTS

vendor:ciscomodel:context directory agentscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:context directory agentscope:eqversion:1.0

Trust: 0.8

sources: JVNDB: JVNDB-2014-001014 // CNNVD: CNNVD-201401-109 // NVD: CVE-2014-0656

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0656
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-0656
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201401-109
value: MEDIUM

Trust: 0.6

VULHUB: VHN-68149
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-0656
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-68149
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-68149 // JVNDB: JVNDB-2014-001014 // CNNVD: CNNVD-201401-109 // NVD: CVE-2014-0656

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-68149 // JVNDB: JVNDB-2014-001014 // NVD: CVE-2014-0656

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201401-109

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201401-109

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001014

PATCH

title:Cisco Context Directory Agent Hidden Input Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0656

Trust: 0.8

title:32367url:http://tools.cisco.com/security/center/viewAlert.x?alertId=32367

Trust: 0.8

sources: JVNDB: JVNDB-2014-001014

EXTERNAL IDS

db:NVDid:CVE-2014-0656

Trust: 2.8

db:BIDid:64701

Trust: 1.4

db:SECTRACKid:1029569

Trust: 1.1

db:OSVDBid:101801

Trust: 1.1

db:JVNDBid:JVNDB-2014-001014

Trust: 0.8

db:CNNVDid:CNNVD-201401-109

Trust: 0.7

db:CISCOid:20140107 CISCO CONTEXT DIRECTORY AGENT HIDDEN INPUT VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-68149

Trust: 0.1

sources: VULHUB: VHN-68149 // BID: 64701 // JVNDB: JVNDB-2014-001014 // CNNVD: CNNVD-201401-109 // NVD: CVE-2014-0656

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-0656

Trust: 1.7

url:http://www.securityfocus.com/bid/64701

Trust: 1.1

url:http://osvdb.org/101801

Trust: 1.1

url:http://www.securitytracker.com/id/1029569

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/90169

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0656

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0656

Trust: 0.8

sources: VULHUB: VHN-68149 // JVNDB: JVNDB-2014-001014 // CNNVD: CNNVD-201401-109 // NVD: CVE-2014-0656

CREDITS

Cisco

Trust: 0.3

sources: BID: 64701

SOURCES

db:VULHUBid:VHN-68149
db:BIDid:64701
db:JVNDBid:JVNDB-2014-001014
db:CNNVDid:CNNVD-201401-109
db:NVDid:CVE-2014-0656

LAST UPDATE DATE

2025-04-11T23:07:14.351000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-68149date:2017-08-29T00:00:00
db:BIDid:64701date:2014-01-07T00:00:00
db:JVNDBid:JVNDB-2014-001014date:2014-01-10T00:00:00
db:CNNVDid:CNNVD-201401-109date:2014-01-09T00:00:00
db:NVDid:CVE-2014-0656date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-68149date:2014-01-08T00:00:00
db:BIDid:64701date:2014-01-07T00:00:00
db:JVNDBid:JVNDB-2014-001014date:2014-01-10T00:00:00
db:CNNVDid:CNNVD-201401-109date:2014-01-09T00:00:00
db:NVDid:CVE-2014-0656date:2014-01-08T21:55:06.380