CVE-2014-0728 is a SQL injection vulnerability in the Java database interface of Cisco Unified Communications Manager (UCM) versions 10.0(1) and earlier. This flaw allows unauthenticated remote attackers to execute arbitrary SQL commands by sending a specially crafted URL. With a CVSS score of 7.5, this vulnerability has high severity, indicating that it is easily exploitable over the network with no authentication required, potentially leading to compromise of confidentiality, integrity, and availability. There is no known public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, suggesting it is not actively exploited in the wild. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.