CVE-2014-0674
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from a client system with a crafted host name, aka Bug ID CSCud10992.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0674
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | video_surveillance_operations_manager | - | |
References
- http://osvdb.org/102409
- http://secunia.com/advisories/56619
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0674
- http://www.securityfocus.com/bid/65111
- http://www.securitytracker.com/id/1029692
- http://www.ubuntu.com/usn/USN-2739-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90651
- http://osvdb.org/102409
- http://secunia.com/advisories/56619
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0674
- http://www.securityfocus.com/bid/65111
- http://www.securitytracker.com/id/1029692
- http://www.ubuntu.com/usn/USN-2739-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90651
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.