NCSC-2026-0136 [1.00] [M/H] Vulnerabilities Fixed in Cisco Unity Connection (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Multiple vulnerabilities fixed in Cisco Unity Connection
- Authenticated attackers can execute code with root privileges
- SSRF vulnerability allows access to internal services
"Cisco has fixed multiple vulnerabilities in Cisco Unity Connection. The vulnerabilities are in the web management interface and the Web Inbox web UI. Authenticated attackers with valid credentials can execute arbitrary code with root privileges, gaining full control over the device. Additionally, a server-side request forgery (SSRF) vulnerability allows manipulation of internal services. Some SSRF attacks can be carried out by unauthenticated attackers due to improper input validation."
no comments yet.