CVE-2014-7991
Cisco Unified Communications Manager < 10.0(1) - Certificate Validation Bypass via SAN Field
Title source: llmDescription
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031181
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98574
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/62267
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=36381
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/71013
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7991
Scores
EPSS
0.0068
EPSS Percentile
48.5%
Details
CWE
CWE-310
Status
published
Products (2)
cisco/unified_communications_manager
10.0
cisco/unified_communications_manager
< 10.0\(1\)
Published
Nov 14, 2014
Tracked Since
Feb 18, 2026