Lucene search

K
ciscoCiscoCISCO-SA-20180221-UCDM
HistoryFeb 21, 2018 - 4:00 p.m.

Cisco Unified Communications Domain Manager Remote Code Execution Vulnerability

2018-02-2116:00:00
tools.cisco.com
56

EPSS

0.022

Percentile

89.6%

A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code.

The vulnerability is due to insecure key generation during application configuration. An attacker could exploit this vulnerability by using a known insecure key value to bypass security protections by sending arbitrary requests using the insecure key to a targeted application. An exploit could allow the attacker to execute arbitrary code.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180221-ucdm [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180221-ucdm”]

Affected configurations

Vulners
Node
ciscounified_communications_domain_managerMatchany
OR
ciscounified_communications_domain_managerMatchany
VendorProductVersionCPE
ciscounified_communications_domain_manageranycpe:2.3:a:cisco:unified_communications_domain_manager:any:*:*:*:*:*:*:*

EPSS

0.022

Percentile

89.6%

Related for CISCO-SA-20180221-UCDM