Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCul24917 and CSCul24908.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/102750 | vdb entry |
http://www.securityfocus.com/bid/65281 | vdb entry |
http://secunia.com/advisories/56818 | third party advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0686 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90852 | vdb entry |
http://tools.cisco.com/security/center/viewAlert.x?alertId=32683 | vendor advisory |