CVE-2014-7991

Cisco Unified Communications Manager < 10.0(1) - Certificate Validation Bypass via SAN Field

Title source: llm
STIX 2.1

Description

The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031181
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98574
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62267
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71013

Scores

EPSS 0.0068
EPSS Percentile 48.5%

Details

CWE
CWE-310
Status published
Products (2)
cisco/unified_communications_manager 10.0
cisco/unified_communications_manager < 10.0\(1\)
Published Nov 14, 2014
Tracked Since Feb 18, 2026