ID

VAR-201402-0201


CVE

CVE-2014-0723


TITLE

Cisco Unified Communications Manager of IP Manager Assistant Interface cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-001397

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum05343. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCum05343. Cisco Unified Communications Manager (CUCM, Unified CM, CallManager) is a call processing component in a unified communication system of Cisco (Cisco). This component provides a scalable, distributed and highly available enterprise IP telephony call processing solution

Trust: 1.98

sources: NVD: CVE-2014-0723 // JVNDB: JVNDB-2014-001397 // BID: 65495 // VULHUB: VHN-68216

AFFECTED PRODUCTS

vendor:ciscomodel:unified communications managerscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:lteversion:10.0(1)

Trust: 0.8

vendor:ciscomodel:unified communications managerscope: - version: -

Trust: 0.6

vendor:ciscomodel:unified communications managerscope:eqversion:0

Trust: 0.3

sources: BID: 65495 // JVNDB: JVNDB-2014-001397 // CNNVD: CNNVD-201402-150 // NVD: CVE-2014-0723

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0723
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-0723
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201402-150
value: MEDIUM

Trust: 0.6

VULHUB: VHN-68216
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-0723
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-68216
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-68216 // JVNDB: JVNDB-2014-001397 // CNNVD: CNNVD-201402-150 // NVD: CVE-2014-0723

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-68216 // JVNDB: JVNDB-2014-001397 // NVD: CVE-2014-0723

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201402-150

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201402-150

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001397

PATCH

title:Cisco Unified Communications Manager IPMA Cross-Site Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0723

Trust: 0.8

title:32824url:http://tools.cisco.com/security/center/viewAlert.x?alertId=32824

Trust: 0.8

sources: JVNDB: JVNDB-2014-001397

EXTERNAL IDS

db:NVDid:CVE-2014-0723

Trust: 2.8

db:BIDid:65495

Trust: 1.4

db:OSVDBid:103222

Trust: 1.1

db:SECTRACKid:1029756

Trust: 1.1

db:JVNDBid:JVNDB-2014-001397

Trust: 0.8

db:CNNVDid:CNNVD-201402-150

Trust: 0.7

db:SECUNIAid:56903

Trust: 0.6

db:CISCOid:20140211 CISCO UNIFIED COMMUNICATIONS MANAGER IPMA CROSS-SITE SCRIPTING VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-68216

Trust: 0.1

sources: VULHUB: VHN-68216 // BID: 65495 // JVNDB: JVNDB-2014-001397 // CNNVD: CNNVD-201402-150 // NVD: CVE-2014-0723

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-0723

Trust: 2.0

url:http://www.securityfocus.com/bid/65495

Trust: 1.1

url:http://osvdb.org/103222

Trust: 1.1

url:http://www.securitytracker.com/id/1029756

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0723

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0723

Trust: 0.8

url:http://secunia.com/advisories/56903

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-68216 // BID: 65495 // JVNDB: JVNDB-2014-001397 // CNNVD: CNNVD-201402-150 // NVD: CVE-2014-0723

CREDITS

Cisco

Trust: 0.3

sources: BID: 65495

SOURCES

db:VULHUBid:VHN-68216
db:BIDid:65495
db:JVNDBid:JVNDB-2014-001397
db:CNNVDid:CNNVD-201402-150
db:NVDid:CVE-2014-0723

LAST UPDATE DATE

2025-04-11T23:17:14.144000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-68216date:2015-09-16T00:00:00
db:BIDid:65495date:2014-02-11T00:00:00
db:JVNDBid:JVNDB-2014-001397date:2014-02-14T00:00:00
db:CNNVDid:CNNVD-201402-150date:2014-02-17T00:00:00
db:NVDid:CVE-2014-0723date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-68216date:2014-02-13T00:00:00
db:BIDid:65495date:2014-02-11T00:00:00
db:JVNDBid:JVNDB-2014-001397date:2014-02-14T00:00:00
db:CNNVDid:CNNVD-201402-150date:2014-02-17T00:00:00
db:NVDid:CVE-2014-0723date:2014-02-13T05:24:51.497