Christopher Schneider

Researcher fromState Farm
#7767of 53,633
35.3Total CVSS
Vulnerabilities · 5
Medium
3
High
2
PT-2021-2542
9.0
2021-04-07
Cisco · Cisco Prime License Manager · CVE-2021-1362
Name of the Vulnerable Software and Affected Versions: Cisco Unified Communications Manager (affected versions not specified) Cisco Unified Communications Manager Session Management Edition (affected versions not specified) Cisco Unified Communications Manager IM & Presence Service (affected versions not specified) Cisco Unity Connection (affected versions not specified) Cisco Prime License Manager (affected versions not specified) Description: The issue is related to improper sanitization of user-supplied input in the SOAP API endpoint, which could allow an authenticated, remote attacker to execute arbitrary code on an affected device. An attacker could exploit this by sending a SOAP API request with crafted parameters to an affected device, potentially allowing the execution of arbitrary code with root privileges on the underlying Linux operating system. Recommendations: For Cisco Unified Communications Manager, update to a version that includes the fix for this issue. For Cisco Unified Communications Manager Session Management Edition, update to a version that includes the fix for this issue. For Cisco Unified Communications Manager IM & Presence Service, update to a version that includes the fix for this issue. For Cisco Unity Connection, update to a version that includes the fix for this issue. For Cisco Prime License Manager, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the SOAP API endpoint until a patch is available.
PT-2021-2572
6.4
2021-04-07
Cisco · Cisco Unified Communications Manager Session Management Edition · CVE-2021-1380
**Name of the Vulnerable Software and Affected Versions** Cisco Unified Communications Manager versions (affected versions not specified) Cisco Unified Communications Manager IM & Presence Service versions (affected versions not specified) Cisco Unified Communications Manager Session Management Edition versions (affected versions not specified) Cisco Unity Connection versions (affected versions not specified) **Description** The web-based management interface of the affected Cisco products does not properly validate user-supplied input, allowing an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an interface user. An attacker could exploit this issue by persuading an interface user to click a crafted link, potentially executing arbitrary script code in the context of the affected interface or accessing sensitive browser-based information. **Recommendations** For Cisco Unified Communications Manager, update to a version that properly validates user-supplied input. For Cisco Unified Communications Manager IM & Presence Service, update to a version that properly validates user-supplied input. For Cisco Unified Communications Manager Session Management Edition, update to a version that properly validates user-supplied input. For Cisco Unity Connection, update to a version that properly validates user-supplied input. As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.