CVE-2014-3292
Description
Cisco Unified Communications Manager RTMT allows authenticated users to read or delete arbitrary files via crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cisco Unified Communications Manager RTMT allows authenticated users to read or delete arbitrary files via crafted URL.
Vulnerability
The Real Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (Unified CM) contains a path traversal vulnerability that allows remote authenticated users to read or delete arbitrary files on the system. This is achieved by sending a crafted URL to the RTMT interface. Affected versions are not explicitly listed in the description, but the bug IDs are CSCuo17302 and CSCuo17199. [1]
Exploitation
An attacker must have valid credentials to authenticate to the Cisco Unified CM web interface. Once authenticated, the attacker can craft a URL that traverses directories to access or delete files outside the intended RTMT directory. No additional privileges or user interaction beyond authentication are required. [1]
Impact
Successful exploitation allows an authenticated attacker to read sensitive files (information disclosure) or delete arbitrary files (denial of service or data loss). The attacker can operate with the privileges of the RTMT application, which typically runs with elevated system access. [1]
Mitigation
Cisco has not released a software update for this vulnerability as of the publication date (2014-06-10). The advisory recommends restricting access to the RTMT interface to trusted users and networks. No workaround is provided in the available references. [1]
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*
- (no CPE)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3292nvdVendor Advisory
- tools.cisco.com/security/center/viewAlert.xnvdVendor Advisory
- www.securitytracker.com/id/1030408nvdThird Party AdvisoryVDB Entry
- secunia.com/advisories/58315nvdPermissions Required
News mentions
0No linked articles in our index yet.