Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be established, which allows man-in-the-middle attackers to obtain sensitive directory information by leveraging a network position between CTS and Cisco Unified Communications Manager (UCM) to block HTTPS traffic, aka Bug ID CSCuj26326.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=34327 | vendor advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3274 | vendor advisory |
http://www.securitytracker.com/id/1030272 | vdb entry third party advisory |