The Certificate Authority Proxy Function (CAPF) CLI implementation in the CSR management feature in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to read or modify arbitrary files via unspecified vectors, aka Bug ID CSCum95464.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=33045 | vendor advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0742 | vendor advisory |
http://www.securitytracker.com/id/1029843 | vdb entry |