The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq86376.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2014-11-14T00:00:00
Updated: 2024-08-06T13:03:27.759Z
Reserved: 2014-10-08T00:00:00
Link: CVE-2014-7991
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-11-14T00:59:03.807
Modified: 2024-11-21T02:18:23.403
Link: CVE-2014-7991
Redhat
No data.