CVE-2014-0738 describes an authentication bypass vulnerability in the Phone Proxy component of Cisco Adaptive Security Appliance (ASA) Software versions 9.1(3) and earlier. An unauthenticated remote attacker could exploit this flaw by injecting a Certificate Trust List (CTL) file, thereby altering trust relationships. While the CVSS score is 4.3 (medium severity) with a low impact on integrity, it has a low EPSS score and FAUCET Risk Score, indicating a low likelihood of exploitation. There is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.