CVE-2014-0736

Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make CAR modifications, aka Bug ID CSCum46468.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
ciscounified_communications_manager
𝑥
≤ 10.0\(1\)
ciscounified_communications_manager
3.3\(5\)
ciscounified_communications_manager
3.3\(5\)sr1
ciscounified_communications_manager
3.3\(5\)sr2a
ciscounified_communications_manager
4.1\(3\)
ciscounified_communications_manager
4.1\(3\)sr1
ciscounified_communications_manager
4.1\(3\)sr2
ciscounified_communications_manager
4.1\(3\)sr3
ciscounified_communications_manager
4.1\(3\)sr4
ciscounified_communications_manager
4.2
ciscounified_communications_manager
4.2.1
ciscounified_communications_manager
4.2.2
ciscounified_communications_manager
4.2.3
ciscounified_communications_manager
4.2.3sr1:sr1
ciscounified_communications_manager
4.2.3sr2:sr2
ciscounified_communications_manager
4.2.3sr2b:sr2b
ciscounified_communications_manager
4.3
ciscounified_communications_manager
10.0
𝑥
= Vulnerable software versions