CVE-2014-3333
Cisco Unity Connection 9.1(1) and 9.1(2) - Authenticated Privilege Escalation via HTTP Intercept
Title source: llmDescription
The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95135
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3333
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59768
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=35200
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/69074
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1030688
Scores
EPSS
0.0313
EPSS Percentile
86.5%
Details
CWE
CWE-264
Status
published
Products (2)
cisco/unity_connection
9.1\(1\)
cisco/unity_connection
9.1\(2\)
Published
Aug 11, 2014
Tracked Since
Feb 18, 2026