ID

VAR-201401-0328


CVE

CVE-2014-0664


TITLE

Cisco Unity Connection Service disruption in the server (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-001024

DESCRIPTION

The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) via unspecified IMAP commands, aka Bug ID CSCul49976. Successful exploiting this issue may allow an attacker to cause excessive CPU consumption, resulting in a denial-of-service condition. This issue is tracked by Cisco Bug ID CSCul49976. Cisco Unity Connection (UC) is a set of voice message platform of Cisco (Cisco). The platform can use voice commands to make calls or listen to messages "hands-free"

Trust: 2.07

sources: NVD: CVE-2014-0664 // JVNDB: JVNDB-2014-001024 // BID: 64772 // VULHUB: VHN-68157 // VULMON: CVE-2014-0664

AFFECTED PRODUCTS

vendor:ciscomodel:unity connectionscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:unity connectionscope:lteversion:9.1(2)

Trust: 0.8

vendor:ciscomodel:unity connectionscope:eqversion:8.6.2

Trust: 0.3

vendor:ciscomodel:unity connectionscope:eqversion:8.6

Trust: 0.3

vendor:ciscomodel:unity connectionscope:eqversion:8.5

Trust: 0.3

vendor:ciscomodel:unity connectionscope:eqversion:8.0

Trust: 0.3

sources: BID: 64772 // JVNDB: JVNDB-2014-001024 // CNNVD: CNNVD-201401-152 // NVD: CVE-2014-0664

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0664
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-0664
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201401-152
value: MEDIUM

Trust: 0.6

VULHUB: VHN-68157
value: MEDIUM

Trust: 0.1

VULMON: CVE-2014-0664
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-0664
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-68157
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-68157 // VULMON: CVE-2014-0664 // JVNDB: JVNDB-2014-001024 // CNNVD: CNNVD-201401-152 // NVD: CVE-2014-0664

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-68157 // JVNDB: JVNDB-2014-001024 // NVD: CVE-2014-0664

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201401-152

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201401-152

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001024

PATCH

title:Cisco Unity Connection Internet Message Access Protocol Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0664

Trust: 0.8

title:32401url:http://tools.cisco.com/security/center/viewAlert.x?alertId=32401

Trust: 0.8

title:Cisco: Cisco Unity Connection Internet Message Access Protocol Denial of Service Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=Cisco-SA-20140110-CVE-2014-0664

Trust: 0.1

sources: VULMON: CVE-2014-0664 // JVNDB: JVNDB-2014-001024

EXTERNAL IDS

db:NVDid:CVE-2014-0664

Trust: 2.9

db:BIDid:64772

Trust: 1.5

db:SECUNIAid:56370

Trust: 1.2

db:SECTRACKid:1029593

Trust: 1.2

db:OSVDBid:101915

Trust: 1.2

db:JVNDBid:JVNDB-2014-001024

Trust: 0.8

db:CNNVDid:CNNVD-201401-152

Trust: 0.7

db:CISCOid:20140110 CISCO UNITY CONNECTION INTERNET MESSAGE ACCESS PROTOCOL DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-68157

Trust: 0.1

db:VULMONid:CVE-2014-0664

Trust: 0.1

sources: VULHUB: VHN-68157 // VULMON: CVE-2014-0664 // BID: 64772 // JVNDB: JVNDB-2014-001024 // CNNVD: CNNVD-201401-152 // NVD: CVE-2014-0664

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-0664

Trust: 1.8

url:http://www.securityfocus.com/bid/64772

Trust: 1.3

url:http://osvdb.org/101915

Trust: 1.2

url:http://www.securitytracker.com/id/1029593

Trust: 1.2

url:http://secunia.com/advisories/56370

Trust: 1.2

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/90234

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0664

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0664

Trust: 0.8

url:www.cisco.com

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20140110-cve-2014-0664

Trust: 0.1

sources: VULHUB: VHN-68157 // VULMON: CVE-2014-0664 // BID: 64772 // JVNDB: JVNDB-2014-001024 // CNNVD: CNNVD-201401-152 // NVD: CVE-2014-0664

CREDITS

Cisco

Trust: 0.3

sources: BID: 64772

SOURCES

db:VULHUBid:VHN-68157
db:VULMONid:CVE-2014-0664
db:BIDid:64772
db:JVNDBid:JVNDB-2014-001024
db:CNNVDid:CNNVD-201401-152
db:NVDid:CVE-2014-0664

LAST UPDATE DATE

2024-11-23T22:49:32.739000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-68157date:2017-08-29T00:00:00
db:VULMONid:CVE-2014-0664date:2017-08-29T00:00:00
db:BIDid:64772date:2014-01-14T00:32:00
db:JVNDBid:JVNDB-2014-001024date:2014-01-14T00:00:00
db:CNNVDid:CNNVD-201401-152date:2014-01-13T00:00:00
db:NVDid:CVE-2014-0664date:2024-11-21T02:02:37.043

SOURCES RELEASE DATE

db:VULHUBid:VHN-68157date:2014-01-10T00:00:00
db:VULMONid:CVE-2014-0664date:2014-01-10T00:00:00
db:BIDid:64772date:2014-01-10T00:00:00
db:JVNDBid:JVNDB-2014-001024date:2014-01-14T00:00:00
db:CNNVDid:CNNVD-201401-152date:2014-01-13T00:00:00
db:NVDid:CVE-2014-0664date:2014-01-10T16:47:06.083