Lucene search

K
ciscoCiscoCISCO-SA-20170621-UCCE
HistoryJun 21, 2017 - 4:00 p.m.

Cisco Unified Contact Center Express Clear Text Authentication Vulnerability

2017-06-2116:00:00
tools.cisco.com
20

EPSS

0.001

Percentile

48.9%

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user.

The vulnerability is due to the XMPP service incorrectly processing an unsecured HTTP port for third-party, remote presence monitoring. A successful exploit could allow the attacker to access the system as another user.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ucce [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ucce”]

Affected configurations

Vulners
Node
ciscounified_contact_center_expressMatchany
OR
ciscounified_contact_center_expressMatchany
VendorProductVersionCPE
ciscounified_contact_center_expressanycpe:2.3:a:cisco:unified_contact_center_express:any:*:*:*:*:*:*:*

EPSS

0.001

Percentile

48.9%

Related for CISCO-SA-20170621-UCCE