ID

VAR-201501-0333


CVE

CVE-2014-8032


TITLE

Cisco WebEx Meetings Server of OutlookAction LI Vulnerable to obtaining important encrypted password information

Trust: 0.8

sources: JVNDB: JVNDB-2014-007560

DESCRIPTION

The OutlookAction LI in Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive encrypted-password information via unspecified vectors, aka Bug IDs CSCuj40453 and CSCuj40449. An attacker can leverage this issue to obtain sensitive information that may aid in further attacks. This issue is being tracked by Cisco bug IDs CSCuj40453 and CSCuj40449. Cisco WebEx Meetings Server (CWMS) is a set of multi-functional conference solutions including audio, video and Web conference in Cisco's WebEx conference solution. A security vulnerability exists in CWMS's OutlookAction LI

Trust: 1.98

sources: NVD: CVE-2014-8032 // JVNDB: JVNDB-2014-007560 // BID: 71947 // VULHUB: VHN-75977

AFFECTED PRODUCTS

vendor:ciscomodel:webex meetings serverscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:webex meetings serverscope: - version: -

Trust: 0.8

vendor:ciscomodel:webex meetings serverscope:eqversion:0

Trust: 0.3

sources: BID: 71947 // JVNDB: JVNDB-2014-007560 // CNNVD: CNNVD-201501-168 // NVD: CVE-2014-8032

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-8032
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-8032
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201501-168
value: MEDIUM

Trust: 0.6

VULHUB: VHN-75977
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-8032
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-75977
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-75977 // JVNDB: JVNDB-2014-007560 // CNNVD: CNNVD-201501-168 // NVD: CVE-2014-8032

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-75977 // JVNDB: JVNDB-2014-007560 // NVD: CVE-2014-8032

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201501-168

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201501-168

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-007560

PATCH

title:Cisco WebEx Meetings Server Password Encryption Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8032

Trust: 0.8

sources: JVNDB: JVNDB-2014-007560

EXTERNAL IDS

db:NVDid:CVE-2014-8032

Trust: 2.8

db:BIDid:71947

Trust: 1.4

db:SECTRACKid:1031517

Trust: 1.1

db:JVNDBid:JVNDB-2014-007560

Trust: 0.8

db:CNNVDid:CNNVD-201501-168

Trust: 0.7

db:VULHUBid:VHN-75977

Trust: 0.1

sources: VULHUB: VHN-75977 // BID: 71947 // JVNDB: JVNDB-2014-007560 // CNNVD: CNNVD-201501-168 // NVD: CVE-2014-8032

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-8032

Trust: 1.7

url:http://www.securityfocus.com/bid/71947

Trust: 1.1

url:http://www.securitytracker.com/id/1031517

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/100564

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8032

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-8032

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-8032

Trust: 0.3

sources: VULHUB: VHN-75977 // BID: 71947 // JVNDB: JVNDB-2014-007560 // CNNVD: CNNVD-201501-168 // NVD: CVE-2014-8032

CREDITS

Cisco

Trust: 0.3

sources: BID: 71947

SOURCES

db:VULHUBid:VHN-75977
db:BIDid:71947
db:JVNDBid:JVNDB-2014-007560
db:CNNVDid:CNNVD-201501-168
db:NVDid:CVE-2014-8032

LAST UPDATE DATE

2024-11-23T21:44:39.414000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-75977date:2017-09-08T00:00:00
db:BIDid:71947date:2015-01-08T00:00:00
db:JVNDBid:JVNDB-2014-007560date:2015-01-13T00:00:00
db:CNNVDid:CNNVD-201501-168date:2015-01-14T00:00:00
db:NVDid:CVE-2014-8032date:2024-11-21T02:18:27.787

SOURCES RELEASE DATE

db:VULHUBid:VHN-75977date:2015-01-09T00:00:00
db:BIDid:71947date:2015-01-08T00:00:00
db:JVNDBid:JVNDB-2014-007560date:2015-01-13T00:00:00
db:CNNVDid:CNNVD-201501-168date:2015-01-09T00:00:00
db:NVDid:CVE-2014-8032date:2015-01-09T02:59:07.727