The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to read or modify arbitrary files via a crafted command, aka Bug ID CSCum95461.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=33046 | vendor advisory |
http://www.securitytracker.com/id/1029843 | vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0741 | vendor advisory |