Vulnerability Fixed in Cisco Unified Communications Manager (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Cisco fixes SSRF vulnerability in Unified Communications Manager
- Attackers can gain root privileges if WebDialer is active
- No public exploit or active exploitation known
"Cisco has fixed a vulnerability in Unified Communications Manager (CM) and CM Session Management Edition. An attacker can exploit this for a Server-Side Request Forgery (SSRF) attack, leading to file and script injection and root privileges. The WebDialer service must be active, which is not default. Cisco is aware of proof-of-concept code but no public exploit or active exploitation observed."
no comments yet.