← Vulnerability feed

Vulnerability record · CVE-2014-3339 · published 12 August 2014

CVE-2014-3339: Cisco unified communications domain manager sql injection vulnerability

Cisco · Unified Communications Domain Manager

Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to execute arbitrary SQL commands via crafted input to unspecified pages, aka Bug ID CSCup74290.

6.5 CVSS 2.0 Medium EPSS 1.5% · top 25.8% CWE-89 · SQL injection
6.5CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to execute arbitrary SQL commands via crafted input to unspecified pages, aka Bug ID CSCup74290.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-3339 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-2198Cisco unified cdm platform software vulnerabilityCisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easie…EPSS 3.6%10.0CVE-2011-1643Cisco unified communications manager information exposure vulnerabilityCisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Pre…EPSS 1.9%9.8CVE-2018-0124Cisco unified communications domain manager vulnerabilityA vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain e…EPSS 5.1%9.0CVE-2014-2197Cisco unified cdm application software permissions and access controls vulnerabilityThe Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 doe…EPSS 2.9%8.8CVE-2018-0364Cisco unified communications domain manager cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker …EPSS 0.71%7.8CVE-2013-1137Cisco unified presence server memory buffer overflow vulnerabilityCisco Unified Presence Server (CUPS) 8.6, 9.0, and 9.1 before 9.1.1 allows remote attackers to cause a denial of service (CPU consumption) via crafte…EPSS 2.3%7.8CVE-2010-2839Cisco unified presence server vulnerabilitySIPD in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) allows remote attackers to cause a denial of service (stack memory corruption …EPSS 1.2%7.8CVE-2010-2840Cisco unified presence server improper input validation vulnerabilityThe Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact fiel…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2014-3339), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.