Boletines de Vulnerabilidades

Cisco Unified Communications Manager Denial of Service Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the web UI of the Self Care Portal. An attacker could exploit this vulnerability by sending crafted HTTP

More info:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-dos-4Ag3yWbD?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Unified%20Communications%20Manager%20Denial%20of%20Service%20Vulnerability&vs_k=1

Identificadores estándar

Propiedad Valor
CVE CVE-2023-20116.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2023-06-08

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT