CVE-2014-3333: Cisco Unity Connection

High severity, CVSS 9.0. EPSS: 3.1% chance of exploitation in the next 30 days.

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.

Affected products

  • Cisco Unity Connection: version 9.1(1) only; version 9.1(2) only

Published 2014-08-11. Last modified 2026-06-17.