CVE-2014-3300 is a critical access control vulnerability affecting Cisco Unified Communications Domain Manager (CDM) and Unified CDM Application Software prior to version 10. This flaw allows unauthenticated remote attackers to modify user information through crafted URLs within the BVSMWeb portal. With a CVSS score of 7.5, it has a high severity, indicating easy exploitation over the network with potential for partial confidentiality, integrity, and availability impact. While not listed in CISA's KEV catalog, exploit modules exist in Metasploit, and it has garnered significant community discussion and media coverage, suggesting a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.1.4CPE matchmatch criteria | cpe:2.3:a:cisco:unified_cdm_application_software:*:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:cisco:unified_cdm_application_software:8.1:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_domain_manager:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.